A vulnerability was found in YFCMF up to 3.0.4. It has...
Moderate severity
Unreviewed
Published
Jun 2, 2023
to the GitHub Advisory Database
•
Updated Nov 6, 2023
Description
Published by the National Vulnerability Database
Jun 2, 2023
Published to the GitHub Advisory Database
Jun 2, 2023
Last updated
Nov 6, 2023
A vulnerability was found in YFCMF up to 3.0.4. It has been rated as problematic. This issue affects some unknown processing of the file app/admin/controller/Ajax.php. The manipulation of the argument controllername leads to path traversal: '../filedir'. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-230543.
References