Metrics
Affected Vendors & Products
Wed, 12 Feb 2025 21:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Fri, 07 Feb 2025 18:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A vulnerability classified as critical has been found in CmsEasy 7.7.7.9. This affects the function deletedir_action/restore_action in the library lib/admin/database_admin.php. The manipulation leads to path traversal. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | |
Title | CmsEasy database_admin.php restore_action path traversal | |
Weaknesses | CWE-22 | |
References |
| |
Metrics |
cvssV2_0
|

Status: PUBLISHED
Assigner: VulDB
Published: 2025-02-07T18:31:04.414Z
Updated: 2025-02-12T20:51:41.660Z
Reserved: 2025-02-07T09:46:50.063Z
Link: CVE-2025-1106

Updated: 2025-02-12T20:46:24.715Z

Status : Received
Published: 2025-02-07T19:15:24.613
Modified: 2025-02-07T19:15:24.613
Link: CVE-2025-1106

No data.