vendor:
CuteNews
by:
Besim ALTINOK
5.5
CVSS
MEDIUM
Arbitrary File Deletion
22
CWE
Product Name: CuteNews
Affected Version From: v2.1.2
Affected Version To: v2.1.2
Patch Exists: NO
Related CWE:
CPE: cutenews
Platforms Tested: Xampp
2020
CuteNews 2.1.2 – Arbitrary File Deletion
In the "Media Manager" area, users can do arbitrarily file deletion. Because the developer did not use the unlink() function as secure. So, can be triggered this vulnerability by a low user account.
Mitigation:
Update to the latest version of CuteNews and ensure that all user accounts have appropriate permissions to prevent unauthorized file deletions.