VulnerabilityModified
CVE-2023-27179
GDidees CMS v3.9.1 and lower was discovered to contain an arbitrary file download vulenrability via the filename parameter at /_admin/imgdownload.php.
HIGH 7.5EPSS 60.8%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 60.8%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
GDidees CMS v3.9.1 and lower was discovered to contain an arbitrary file download vulenrability via the filename parameter at /_admin/imgdownload.php.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 60.79% probability · 99th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-434
- Affected
- gdidees/gdidees cms
- Source
- cve@mitre.org
References
- http://packetstormsecurity.com/files/171894/GDidees-CMS-3.9.1-Local-File-Disclosure-Directory-Traversal.html
- https://gist.github.com/Hadi999/516aa25b953b0cba57089a0c11b1305bThird Party Advisory
- https://knowledge-base.secureflag.com/vulnerabilities/unrestricted_file_download/unrestricted_file_download_vulnerability.htmlThird Party Advisory
- https://www.gdidees.eu/cms-1-0.htmlProduct
- http://packetstormsecurity.com/files/171894/GDidees-CMS-3.9.1-Local-File-Disclosure-Directory-Traversal.html
- https://gist.github.com/Hadi999/516aa25b953b0cba57089a0c11b1305bThird Party Advisory
- https://knowledge-base.secureflag.com/vulnerabilities/unrestricted_file_download/unrestricted_file_download_vulnerability.htmlThird Party Advisory
- https://www.gdidees.eu/cms-1-0.htmlProduct
- https://packetstorm.news/files/id/171894
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.