BlueCMS 1.6 suffers from Arbitrary File Deletion via the file_name parameter in an /admin/database.php?act=del request.
The product makes files or directories accessible to unauthorized actors, even though they should not be.
Link | Tags |
---|---|
https://github.com/source-trace/bluecms/issues/1 | third party advisory |
https://gist.github.com/yihanjinchangtai/215ea4bf71edb0ac9df33b221b63a3a9 | third party advisory |