CVE-2023-29962

S-CMS v5.0 was discovered to contain an arbitrary file read vulnerability.
Configurations

Configuration 1 (hide)

cpe:2.3:a:s-cms:s-cms:5.0:*:*:*:*:*:*:*

History

10 Jan 2024, 16:51

Type Values Removed Values Added
First Time S-cms s-cms
S-cms
References () https://gist.github.com/superjock1988/546df50f8251cb2c99adda4351098528 - () https://gist.github.com/superjock1988/546df50f8251cb2c99adda4351098528 - Third Party Advisory
References () https://github.com/superjock1988/debug/blob/main/s-cms.md - () https://github.com/superjock1988/debug/blob/main/s-cms.md - Exploit
CWE CWE-22
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
CPE cpe:2.3:a:s-cms:s-cms:5.0:*:*:*:*:*:*:*

04 Jan 2024, 06:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-01-04 06:15

Updated : 2024-01-10 16:51


NVD link : CVE-2023-29962

Mitre link : CVE-2023-29962

CVE.ORG link : CVE-2023-29962


JSON object : View

Products Affected

s-cms

  • s-cms
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')