CVE-2023-35860

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
13/06/2024
Last modified:
14/08/2024

Description

A Directory Traversal vulnerability in Modern Campus - Omni CMS 2023.1 allows a remote, unauthenticated attacker to enumerate file system information via the dir parameter to listing.php or rss.php.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:moderncampus:omni_cms:2023.1:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools