CVE-2018-18891

HIGH

MiniCMS 1.10 - Unauthenticated File Deletion via /mc-admin/post.php

Title source: llm
STIX 2.1

Description

MiniCMS 1.10 allows file deletion via /mc-admin/post.php?state=delete&delete= because the authentication check occurs too late.

References (2)

Core 2

Scores

CVSS v3 7.5
EPSS 0.0118
EPSS Percentile 63.6%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Details

CWE
CWE-287
Status published
Products (1)
1234n/minicms 1.10
Published Nov 01, 2018
Tracked Since Feb 18, 2026