CVE-2018-13980

MEDIUM NUCLEI

Zeta-producer Zeta Producer < 14.2.1 - Path Traversal

Title source: rule

Description

The websites that were built from Zeta Producer Desktop CMS before 14.2.1 are vulnerable to unauthenticated file disclosure if the plugin "filebrowser" is installed, because of assets/php/filebrowser/filebrowser.main.php?file=../ directory traversal.

Exploits (1)

exploitdb WRITEUP
by SEC Consult · textwebappsphp
https://www.exploit-db.com/exploits/45016

Nuclei Templates (1)

Zeta Producer Desktop CMS <14.2.1 - Local File Inclusion
MEDIUMby wisnupramoedya

Scores

CVSS v3 5.5
EPSS 0.1466
EPSS Percentile 94.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-22
Status published
Products (1)
zeta-producer/zeta_producer < 14.2.1
Published Jul 16, 2018
Tracked Since Feb 18, 2026