CVE-2017-16903

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
20/11/2017
Last modified:
13/05/2026

Description

LvyeCMS through 3.1 allows remote attackers to upload and execute arbitrary PHP code via directory traversal sequences in the dir parameter, in conjunction with PHP code in the content parameter, within a template Style add request to index.php.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:lvyecms_project:lvyecms:*:*:*:*:*:*:*:* 3.1 (including)