MEDIUM
HongCMS 3.0.0 allows arbitrary file deletion via a ../ in the file parameter to admin/index.php/database/ajax?action=delete, a similar issue to CVE-2018-16774
Published Sep 25, 2019
6.5
MEDIUMCVSS 3.1
EPSS 1.12%
Description
Affected products
Remediation
References (1)
Change history (0)
No recorded changes yet.