SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2018-13980

The websites that were built from Zeta Producer Desktop CMS before 14.2.1 are vulnerable to unauthenticated file disclosure if the plugin "filebrowser" is installed, because of assets/php/filebrowser/filebrowser.main.php?file=../ directory traversal.

MEDIUM 5.5EPSS 6.90%

Does this matter?

Lower severity and a low EPSS score (6.90%). Track it; it rarely justifies an emergency change on its own.

Description

The websites that were built from Zeta Producer Desktop CMS before 14.2.1 are vulnerable to unauthenticated file disclosure if the plugin "filebrowser" is installed, because of assets/php/filebrowser/filebrowser.main.php?file=../ directory traversal.

CVSS 3.1
5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS
6.90% probability · 94th percentile
CISA KEV
Not listed
Weakness
CWE-22
Affected
zeta-producer/zeta producer
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.