490
VMScore

CVE-2019-8407

Published: 17/02/2019 Updated: 19/02/2019
CVSS v2 Base Score: 5.5 | Impact Score: 4.9 | Exploitability Score: 8
CVSS v3 Base Score: 6.5 | Impact Score: 5.2 | Exploitability Score: 1.2
VMScore: 490
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:N

Vulnerability Summary

HongCMS 3.0.0 allows arbitrary file read and write operations via a ../ in the filename parameter to the admin/index.php/language/edit URI.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

hongcms project hongcms 3.0.0