CVE-2018-18257
HIGHBageCMS 3.1.3 - Unauthenticated Path Traversal and Arbitrary File Deletion via Template Batch Endpoint
Title source: llmDescription
An issue was discovered in BageCMS 3.1.3. An attacker can delete any files and folders on the web server via an index.php?r=admini/template/batch&command=deleteFile&fileName= or index.php?r=admini/template/batch&command=deleteFolder&folderName=../ directory traversal URI.
References (1)
Core 1
Core References
Exploit, Third Party Advisory x_refsource_misc
https://github.com/rakjong/vuln/blob/master/Bagecms_vuln_2.pdf
Scores
CVSS v3
7.5
EPSS
0.0155
EPSS Percentile
72.0%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Details
CWE
CWE-22
Status
published
Products (1)
bagesoft/bagecms
3.1.3
Published
Oct 11, 2018
Tracked Since
Feb 18, 2026