Vulnerability Description
In Gxlcms QY v1.0.0713, Lib\Lib\Action\Admin\DataAction.class.php allows remote attackers to delete any file via directory traversal sequences in the id parameter of an Admin-Data-del request.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Gxlcms | Gxlcms Qy | 1.0.0713 |
Related Weaknesses (CWE)
References
- http://www.atksec.com/cve/GxlcmsQY-v1.0.0713-filedelete/index.htmlExploitThird Party Advisory
- http://www.atksec.com/cve/GxlcmsQY-v1.0.0713-filedelete/index.htmlExploitThird Party Advisory
FAQ
What is CVE-2018-9850?
CVE-2018-9850 is a vulnerability with a CVSS score of 7.5 (HIGH). In Gxlcms QY v1.0.0713, Lib\Lib\Action\Admin\DataAction.class.php allows remote attackers to delete any file via directory traversal sequences in the id parameter of an Admin-Data-del request.
How severe is CVE-2018-9850?
CVE-2018-9850 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-9850?
Check the references section above for vendor advisories and patch information. Affected products include: Gxlcms Gxlcms Qy.