A Path Traversal vulnerability was discovered in MOPCMS through 2018-11-30, leading to deletion of unexpected critical files. The exploitation point is in the "column management" function. The path added to the column is not verified. When a column is deleted by an attacker, the corresponding directory is deleted, as demonstrated by ./ to delete the entire web site.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2019-02-22T16:00:00

Updated: 2024-08-04T21:31:37.614Z

Reserved: 2019-02-22T00:00:00

Link: CVE-2019-9015

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2019-02-22T16:29:00.263

Modified: 2019-02-22T19:38:47.093

Link: CVE-2019-9015

cve-icon Redhat

No data.