AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2018-12939

MEDIUM · CVSS 6.5 EPSS 1.97%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2018-07-31 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2018-12939
Severity
MEDIUM
CVSS
6.5
EPSS
1.97%

Original NVD Description

A directory traversal flaw in SeedDMS (formerly LetoDMS and MyDMS) before 5.1.8 allows an authenticated attacker to write to (or potentially delete) arbitrary files via a .. (dot dot) in the "op/op.UploadChunks.php" "qquuid" parameter. NOTE: this can be leveraged to execute arbitrary code by using CVE-2018-12940.