GDidees CMS v3.9.1 was discovered to contain a source code disclosure vulnerability by the backup feature which is accessible via /_admin/backup.php.
The product makes files or directories accessible to unauthorized actors, even though they should not be.
Link | Tags |
---|---|
https://www.gdidees.eu/cms-1-0.html | product |
https://github.com/chamilo/pclzip | not applicable |
https://gist.github.com/Hadi999/d691e35d4f494d37ccc5638e68227606 | third party advisory exploit |