Vulnerability Details CVE-2018-13980
The websites that were built from Zeta Producer Desktop CMS before 14.2.1 are vulnerable to unauthenticated file disclosure if the plugin "filebrowser" is installed, because of assets/php/filebrowser/filebrowser.main.php?file=../ directory traversal.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.113
EPSS Ranking 93.2%
CVSS Severity
CVSS v3 Score 5.5
CVSS v2 Score 2.1
Products affected by CVE-2018-13980
-
cpe:2.3:a:zeta-producer:zeta_producer:11.0.3
-
cpe:2.3:a:zeta-producer:zeta_producer:11.0.4
-
cpe:2.3:a:zeta-producer:zeta_producer:11.1.0
-
cpe:2.3:a:zeta-producer:zeta_producer:11.1.1
-
cpe:2.3:a:zeta-producer:zeta_producer:11.2.0
-
cpe:2.3:a:zeta-producer:zeta_producer:11.2.1
-
cpe:2.3:a:zeta-producer:zeta_producer:11.2.2
-
cpe:2.3:a:zeta-producer:zeta_producer:11.2.3
-
cpe:2.3:a:zeta-producer:zeta_producer:11.3.0
-
cpe:2.3:a:zeta-producer:zeta_producer:11.4.0
-
cpe:2.3:a:zeta-producer:zeta_producer:11.4.1
-
cpe:2.3:a:zeta-producer:zeta_producer:11.4.2
-
cpe:2.3:a:zeta-producer:zeta_producer:12.0.0
-
cpe:2.3:a:zeta-producer:zeta_producer:12.0.1
-
cpe:2.3:a:zeta-producer:zeta_producer:12.0.2
-
cpe:2.3:a:zeta-producer:zeta_producer:12.1.0
-
cpe:2.3:a:zeta-producer:zeta_producer:12.2.0
-
cpe:2.3:a:zeta-producer:zeta_producer:12.5.4
-
cpe:2.3:a:zeta-producer:zeta_producer:12.5.6
-
cpe:2.3:a:zeta-producer:zeta_producer:12.5.7
-
cpe:2.3:a:zeta-producer:zeta_producer:13.0.0
-
cpe:2.3:a:zeta-producer:zeta_producer:13.1.0
-
cpe:2.3:a:zeta-producer:zeta_producer:13.2.0
-
cpe:2.3:a:zeta-producer:zeta_producer:13.2.1
-
cpe:2.3:a:zeta-producer:zeta_producer:13.3.0
-
cpe:2.3:a:zeta-producer:zeta_producer:14.0
-
cpe:2.3:a:zeta-producer:zeta_producer:14.0.1
-
cpe:2.3:a:zeta-producer:zeta_producer:14.1.0
-
cpe:2.3:a:zeta-producer:zeta_producer:14.2.0