Back

LOW

BigTree 4.3 allows full path disclosure via authenticated admin/news/ input that triggers a syntax error

Published Dec 23, 2018

Description

BigTree 4.3 allows full path disclosure via authenticated admin/news/ input that triggers a syntax error. NOTE: This has been disputed with the following reasoning: "The issue reported requires full developer level access to the content management system where cross site scripting is not an issue -- you already have full control of the CMS including running arbitrary PHP.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Dec 23, 2018
Updated Aug 5, 2024
Reserved Dec 23, 2018
CISA Vulnrichment
Updated Jul 23, 2024
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a