Vulnerability Description
An issue was discovered in PHPYun V4.6. There is a vulnerability that can delete any file or directory via the "admin/index.php?m=database&c=del" sql parameter because del_action() in admin/model/database.class.php mishandles this parameter.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Phpyun | Phpyun | 4.6 |
References
- http://str3am.me/2018/10/23/CVE_01/#moreBroken LinkThird Party AdvisoryURL Repurposed
- http://str3am.me/2018/10/23/CVE_01/#moreBroken LinkThird Party AdvisoryURL Repurposed
FAQ
What is CVE-2018-18626?
CVE-2018-18626 is a vulnerability with a CVSS score of 7.5 (HIGH). An issue was discovered in PHPYun V4.6. There is a vulnerability that can delete any file or directory via the "admin/index.php?m=database&c=del" sql parameter because del_action() in admin/model/data...
How severe is CVE-2018-18626?
CVE-2018-18626 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-18626?
Check the references section above for vendor advisories and patch information. Affected products include: Phpyun Phpyun.