CVE-2018-17934
27.11.2018, 20:29
NUUO CMS All versions 3.3 and prior the application allows external input to construct a pathname that is able to be resolved outside the intended directory. This could allow an attacker to impersonate a legitimate user, obtain restricted information, or execute arbitrary code.
Vendor | Product | Version |
---|---|---|
nuuo | nuuo_cms | 𝑥 ≤ 3.3 |
𝑥
= Vulnerable software versions