peter bassill · operator
$ cve CVE-2018-13980 JSON

CVE-2018-13980 EXPLOIT

5.5
MEDIUM · CVSS 3.1 · EPSS 6.9% (pctl 94)

Patch early

A public exploit exists.

Description

The websites that were built from Zeta Producer Desktop CMS before 14.2.1 are vulnerable to unauthenticated file disclosure if the plugin "filebrowser" is installed, because of assets/php/filebrowser/filebrowser.main.php?file=../ directory traversal.

Scoring

CVSS5.5 (MEDIUM, v3.1)
VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS6.9% — more likely to be exploited than 94% of all CVEs
WeaknessCWE-22
On CISA KEVno
Public exploityes
Published2018-07-16
Last modified2026-06-17

Affected (1)

VendorProduct
zeta-producerzeta producer

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD