vendor:
WinduCMS
by:
Maciek Krupa
7,5
CVSS
HIGH
Local File Disclosure
200
CWE
Product Name: WinduCMS
Affected Version From: 3.1
Affected Version To: 3.1
Patch Exists: Yes
Related CWE: N/A
CPE: a:windu:winducms
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Linux Debian 9
2017
WinduCMS <= 3.1 - Local File Disclosure
Local File Disclosure vulnerability exists in WinduCMS through a vulnerable PHPMailer version 5.2.1 used here. It requires a contact form present on the website. An example of the vulnerable code is {{W name=contactForm inputs="name" email="root@localhost"}}
Mitigation:
Upgrade to the latest version of WinduCMS and PHPMailer.