CmsEasy v7.7.7.9 was discovered to contain a local file inclusion vunerability via the file_get_contents function in the fckedit_action method of /admin/template_admin.php. This vulnerability allows attackers to read arbitrary files.
References
Configurations
No configuration.
History
No history.
Information
Published : 2024-05-07 19:15
Updated : 2024-07-03 01:59
NVD link : CVE-2024-34315
Mitre link : CVE-2024-34315
CVE.ORG link : CVE-2024-34315
JSON object : View
Products Affected
No product.
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')