lms version <= LMS_011123 contains a Local File Disclosure vulnerability in File reading functionality in LMS module that can result in Possible to read files on the server. This attack appear to be exploitable via GET parameter. This vulnerability appears to have been fixed in after commit 254765e.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2018-06-26T16:00:00
Updated: 2024-08-05T12:40:47.205Z
Reserved: 2018-06-01T00:00:00
Link: CVE-2018-1000535
Vulnrichment
No data.
NVD
Status : Modified
Published: 2018-06-26T16:29:01.993
Modified: 2024-11-21T03:40:08.657
Link: CVE-2018-1000535
Redhat
No data.