CVE-2018-16141

Publication date

2018-08-30 05:00:00

Family

mitre

State

PUBLISHED

Description

ThinkCMF X2.2.3 has an arbitrary file deletion vulnerability in do_avatar in applicationUserControllerProfileController.class.php via an imgurl parameter with a .. sequence. A member user can delete any file on a Windows server.