Vulnerability Description
cmseasy v7.7.7.7 20230520 was discovered to contain a path traversal vulnerability via the add_action method at lib/admin/language_admin.php. This vulnerability allows attackers to execute arbitrary code and perform a local file inclusion.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cmseasy | Cmseasy | 7.7.7.7 |
Related Weaknesses (CWE)
References
- https://blog.pumpk1n.com/2023/06/06/cmseasy-v7-7-7-7-20230520-path-traversal/ExploitThird Party Advisory
- https://blog.pumpk1n.com/2023/06/06/cmseasy-v7-7-7-7-20230520-path-traversal/ExploitThird Party Advisory
FAQ
What is CVE-2023-34880?
CVE-2023-34880 is a vulnerability with a CVSS score of 9.8 (CRITICAL). cmseasy v7.7.7.7 20230520 was discovered to contain a path traversal vulnerability via the add_action method at lib/admin/language_admin.php. This vulnerability allows attackers to execute arbitrary c...
How severe is CVE-2023-34880?
CVE-2023-34880 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2023-34880?
Check the references section above for vendor advisories and patch information. Affected products include: Cmseasy Cmseasy.