vendor:
PikaCMS
by:
KnocKout
5.5
CVSS
MEDIUM
Local File Disclosure
CWE
Product Name: PikaCMS
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
PikaCMS Local File Disclosure Vulnerability
PikaCMS is prone to multiple local file-disclosure vulnerabilities because it fails to adequately validate user-supplied input. Exploiting these vulnerabilities may allow an attacker to obtain potentially sensitive information from local files on computers running the vulnerable application. This may aid in further attacks.
Mitigation:
Implement proper input validation and sanitization techniques to prevent unauthorized file access.