MiniCMS 1.10 allows file deletion via /mc-admin/post.php?state=delete&delete= because the authentication check occurs too late.
                
            References
                    | Link | Resource | 
|---|---|
| https://github.com/AvaterXXX/MiniCms/blob/master/Authentication%20and%20Information%20Exposure.md#authentication-vulnerability | Exploit Third Party Advisory | 
| https://www.patec.cn/newsshow.php?cid=24&id=135 | Exploit Third Party Advisory | 
| https://github.com/AvaterXXX/MiniCms/blob/master/Authentication%20and%20Information%20Exposure.md#authentication-vulnerability | Exploit Third Party Advisory | 
| https://www.patec.cn/newsshow.php?cid=24&id=135 | Exploit Third Party Advisory | 
Configurations
                    History
                    No history.
Information
                Published : 2018-11-01 01:29
Updated : 2024-11-21 03:56
NVD link : CVE-2018-18891
Mitre link : CVE-2018-18891
CVE.ORG link : CVE-2018-18891
JSON object : View
Products Affected
                1234n
- minicms
CWE
                
                    
                        
                        CWE-287
                        
            Improper Authentication
