Back to Database
Status published
High
CVE-2018-13021
An issue was discovered in HongCMS 3.0.0. There is an...
Vulnerability Description
An issue was discovered in HongCMS 3.0.0. There is an Arbitrary Script File Upload issue that can result in PHP code execution via the admin/index.php/template/upload URI.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2018-13021
Credits & Attribution
No credits recorded in the NVD database.
References
More from hongcms project
View All →CVE-2022-32412
An issue in the /template/edit component of HongCMS v3.0 allows...
High
7.2
CVE-2022-32411
An issue in the languages config file of HongCMS v3.0...
High
7.2
CVE-2022-28523
HongCMS 3.0.0 allows arbitrary file deletion via the component /admin/index.php/template/ajax?action=delete....
High
8.1
CVE-2020-21643
Cross Site Scripting (XSS) vulnerability in HongCMS 3.0 allows attackers...
Unknown
0
CVE-2020-21431
HongCMS v3.0 contains an arbitrary file read and write vulnerability...
Medium
6.5
Affected Vendor
hongcms project
View all reports →Affected Software
hongcms
Vulnerable Versions:
3.0.0
Timeline
Official Publish:
June 29th, 2018
Last Modified:
August 5th, 2024
Added to House:
July 20th, 2026
CVSS Vectors
V3:
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.