Metrics
Affected Vendors & Products
Fri, 28 Feb 2025 23:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Cmseasy
Cmseasy cmseasy |
|
CPEs | cpe:2.3:a:cmseasy:cmseasy:7.7.7.9:*:*:*:*:*:*:* | |
Vendors & Products |
Cmseasy
Cmseasy cmseasy |
Wed, 12 Feb 2025 21:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Mon, 03 Feb 2025 00:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A vulnerability classified as critical was found in CmsEasy 7.7.7.9. This vulnerability affects the function backAll_action in the library lib/admin/database_admin.php of the file /index.php?case=database&act=backAll&admin_dir=admin&site=default. The manipulation of the argument select[] leads to path traversal. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | |
Title | CmsEasy index.php backAll_action path traversal | |
Weaknesses | CWE-22 | |
References |
| |
Metrics |
cvssV2_0
|

Status: PUBLISHED
Assigner: VulDB
Published: 2025-02-03T00:31:04.880Z
Updated: 2025-02-12T20:41:37.613Z
Reserved: 2025-02-02T07:59:35.782Z
Link: CVE-2025-0973

Updated: 2025-02-12T20:40:33.174Z

Status : Analyzed
Published: 2025-02-03T01:15:07.263
Modified: 2025-02-28T22:16:37.477
Link: CVE-2025-0973

No data.