CVE-2018-13980 EXPLOIT
5.5
MEDIUM · CVSS 3.1 · EPSS 6.9% (pctl 94)
Patch early
A public exploit exists.
Description
The websites that were built from Zeta Producer Desktop CMS before 14.2.1 are vulnerable to unauthenticated file disclosure if the plugin "filebrowser" is installed, because of assets/php/filebrowser/filebrowser.main.php?file=../ directory traversal.
Scoring
| CVSS | 5.5 (MEDIUM, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
| EPSS | 6.9% — more likely to be exploited than 94% of all CVEs |
| Weakness | CWE-22 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2018-07-16 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| zeta-producer | zeta producer |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Zeta Producer Desktop CMS 14.2.0 - Remote Code Execution / Local File Disclosure | 2018-07-13 |
References
- http://packetstormsecurity.com/files/148537/Zeta-Producer-Desktop-CMS-14.2.0-Code-Execution-File-Disclosure.html
- https://www.exploit-db.com/exploits/45016/
- https://www.sec-consult.com/en/blog/advisories/remote-code-execution-local-file-disclosure-zeta-producer-desktop-cms/
- http://packetstormsecurity.com/files/148537/Zeta-Producer-Desktop-CMS-14.2.0-Code-Execution-File-Disclosure.html
- https://www.exploit-db.com/exploits/45016/
- https://www.sec-consult.com/en/blog/advisories/remote-code-execution-local-file-disclosure-zeta-producer-desktop-cms/
→ the Explorer · watch your stack · NVD