CVE-2023-34880

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
15/06/2023
Last modified:
26/06/2023

Description

cmseasy v7.7.7.7 20230520 was discovered to contain a path traversal vulnerability via the add_action method at lib/admin/language_admin.php. This vulnerability allows attackers to execute arbitrary code and perform a local file inclusion.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:cmseasy:cmseasy:7.7.7.7:20230520:*:*:*:*:*:*