TROYANOSYVIRUS
Back to CVEs

CVE-2018-1000535

HIGH
7.5

Description

lms version <= LMS_011123 contains a Local File Disclosure vulnerability in File reading functionality in LMS module that can result in Possible to read files on the server. This attack appear to be exploitable via GET parameter. This vulnerability appears to have been fixed in after commit 254765e.

CVE Details

CVSS v3.1 Score7.5
SeverityHIGH
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack VectorNETWORK
ComplexityLOW
Privileges RequiredNONE
User InteractionNONE
Published6/26/2018
Last Modified11/21/2024
Sourcenvd
Honeypot Sightings0

Affected Products

lms:lms

Weaknesses (CWE)

CWE-200

IOC Correlations

No correlations recorded

This product uses data from the NVD API but is not endorsed or certified by the NVD.