MEDIUM
CMS Made Simple (CMSMS) through 2.2.7 allows physical path leakage via an invalid /index.php?page= value, a crafted URI starting with /index.php?mact=Search, or a direct request to /admin/header.php, /admin/footer.php, /lib/tasks/class.ClearCache.task.php, or /lib/tasks/class.CmsSecurityCheck.task.php
Published Apr 13, 2018
5.3
MEDIUMCVSS 3.0
EPSS 1.19%
Description
Affected products
Remediation
References (2)
Change history (0)
No recorded changes yet.