CmsEasy v7.7.7.9 was discovered to contain a local file inclusion vunerability via the file_get_contents function in the fckedit_action method of /admin/template_admin.php. This vulnerability allows attackers to read arbitrary files.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NCmseasy
APPCmseasy7.7.7.9
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Path Traversal
CWE
Related vulnerabilities
CVE-2023-34880CRITICAL9.8PL ✓same product
CmsEasy — path traversal i wykonanie dowolnego kodu (RCE)
CVE-2024-31551HIGH7.5same product
Directory Traversal vulnerability in lib/admin/image.admin.php in cmseasy v7.7.7.9 20240105 allows attackers t...
CVE-2020-18406HIGH7.5same product
An issue was discovered in cmseasy v7.0.0 that allows user credentials to be sent in clear text due to no encr...
CVE-2021-42643HIGH8.8same product
cmseasy V7.7.5_20211012 is affected by an arbitrary file write vulnerability. Through this vulnerability, a PH...
CVE-2018-11679HIGH8.8same product
An issue was discovered in CmsEasy 6.1_20180508. There is a CSRF vulnerability that can add an article via /in...