MEDIUM
In CMS Made Simple (CMSMS) through 2.2.7, the "file rename" operation in the admin dashboard contains a sensitive information disclosure vulnerability, exploitable by an admin user, that can cause DoS by moving config.php to the upload/ directory
Published Apr 27, 2018
6.5
MEDIUMCVSS 3.0
EPSS 1.20%
Description
Affected products
Remediation
Metrics
References (1)
Change history (0)
No recorded changes yet.