Vulnerability Description
Gxlcms uses an unsafe character-replacement approach in an attempt to restrict access, which allows remote attackers to read arbitrary files via modified pathnames in the s parameter to index.php, related to Lib/Admin/Action/TplAction.class.php and Lib/Admin/Common/function.php.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Gxlcms | Gxlcms | - |
References
- https://github.com/Blck4/blck4/blob/master/Gxlcms%20POC.phpExploitThird Party Advisory
- https://github.com/Blck4/blck4/blob/master/Gxlcms%20POC.phpExploitThird Party Advisory
FAQ
What is CVE-2017-14979?
CVE-2017-14979 is a vulnerability with a CVSS score of 7.5 (HIGH). Gxlcms uses an unsafe character-replacement approach in an attempt to restrict access, which allows remote attackers to read arbitrary files via modified pathnames in the s parameter to index.php, rel...
How severe is CVE-2017-14979?
CVE-2017-14979 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-14979?
Check the references section above for vendor advisories and patch information. Affected products include: Gxlcms Gxlcms.