Vulnerability Description
An arbitrary file read vulnerability in DamiCMS v6.0.0 allows remote authenticated administrators to read any files in the server via a crafted /admin.php?s=Tpl/Add/id/ URI.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Damicms | Damicms | 6.0.0 |
Related Weaknesses (CWE)
References
- https://gist.github.com/feric/98180bad0a73716e143ff8dc03fda12fExploitThird Party Advisory
- https://gist.github.com/feric/98180bad0a73716e143ff8dc03fda12fExploitThird Party Advisory
FAQ
What is CVE-2018-14831?
CVE-2018-14831 is a vulnerability with a CVSS score of 4.9 (MEDIUM). An arbitrary file read vulnerability in DamiCMS v6.0.0 allows remote authenticated administrators to read any files in the server via a crafted /admin.php?s=Tpl/Add/id/ URI.
How severe is CVE-2018-14831?
CVE-2018-14831 has been rated MEDIUM with a CVSS base score of 4.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-14831?
Check the references section above for vendor advisories and patch information. Affected products include: Damicms Damicms.