PT-2023-20993 · Unknown · Gdidees Cms

·

CVE-2023-27180

·

Published

2023-04-07

·

Updated

2023-04-13

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions GDidees CMS version 3.9.1
Description A source code disclosure issue was found in the backup feature of GDidees CMS, accessible via the "/ admin/backup.php" endpoint. This allows for potential access to sensitive information.
Recommendations For GDidees CMS version 3.9.1, consider restricting access to the "/ admin/backup.php" endpoint until a patch is available. As a temporary workaround, disabling the backup feature may help minimize the risk of exploitation.

Exploit

Fix

Files Accessible to External Parties

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-27180

Affected Products

Gdidees Cms