ZeroHour

CVE-2018-13980

PoC ×3
CVSS 3.1
5.5 medium
EPSS
7%p94
Published
()
Modified
Description

The websites that were built from Zeta Producer Desktop CMS before 14.2.1 are vulnerable to unauthenticated file disclosure if the plugin "filebrowser" is installed, because of assets/php/filebrowser/filebrowser.main.php?file=../ directory traversal.

Vendors
zeta-producer
Products
zeta producer
Weakness
CWE-22
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.