CVE-2024-3216217.04.2024, 19:15CMSeasy 7.7.7.9 is vulnerable to Arbitrary file deletion.EnginsightProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVectorNISTNIST4.3 MEDIUMNETWORKLOWLOWCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:NmitreCNA------CISA-ADPADP4.3 MEDIUMNETWORKLOWLOWCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:NCVEADP------Base ScoreCVSS 3.xEPSS ScorePercentile: 28%VendorProductVersioncmseasycmseasy7.7.7.9𝑥= Vulnerable software versionsKnown Exploits!https://github.com/XiLitter/CMS_vulnerability-discovery/blob/main/CMSeasy_7.7.7_file_deletion.mdhttps://github.com/XiLitter/CMS_vulnerability-discovery/blob/main/CMSeasy_7.7.7_file_deletion.mdCommon Weakness EnumerationCWE-791 - Incomplete Filtering of Special ElementsThe software receives data from an upstream component, but does not completely filter special elements before sending it to a downstream component.Referenceshttp://cmseasy.comhttps://github.com/XiLitter/CMS_vulnerability-discovery/blob/main/CMSeasy_7.7.7_file_deletion.mdhttp://cmseasy.comhttps://github.com/XiLitter/CMS_vulnerability-discovery/blob/main/CMSeasy_7.7.7_file_deletion.md