ZeroHour

CVE-2018-18258

PoC
CVSS 3.0
9.8 critical
EPSS
1%p73
Published
()
Modified
Description

An issue was discovered in BageCMS 3.1.3. The attacker can execute arbitrary PHP code on the web server and can read any file on the web server via an index.php?r=admini/template/updateTpl&filename= URI.

Vendors
bagesoft
Products
bagecms
Weakness
CWE-94
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.