PT-2026-23695 · Unknown · Surreal Todo

Published

2026-03-06

·

Updated

2026-03-06

·

CVE-2018-25184

CVSS v3.1

6.2

Medium

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Surreal ToDo version 0.6.1.2
Description The application contains a local file inclusion issue that allows unauthenticated attackers to read arbitrary files. Attackers can manipulate the content parameter in the 'index.php' file to supply directory traversal sequences. This allows access to sensitive system files, such as configuration and initialization files. The vulnerable API endpoint is '/index.php'. The vulnerable parameter is content.
Recommendations Update to a newer version that contains a fix for this vulnerability. As a temporary workaround, restrict access to the 'index.php' file.

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2018-25184

Affected Products

Surreal Todo