April 11, 2023, 12:15 p.m. |

National Vulnerability Database web.nvd.nist.gov

GDidees CMS v3.9.1 and lower was discovered to contain an arbitrary file download vulenrability via the filename parameter at /_admin/imgdownload.php.

cms cve download file filename parameter php vulenrability

Information Security Engineers

@ D. E. Shaw Research | New York City

Technology Security Analyst

@ Halton Region | Oakville, Ontario, Canada

Senior Cyber Security Analyst

@ Valley Water | San Jose, CA

Senior SecOps Security Architect

@ SGS | Madrid, Spain

Auditeur(trice) de configuration et d’architecture - Cybersécurité - Toulouse

@ Sopra Steria | Colomiers, France

Cybersecurity - staż SantanderTech

@ Santander | Wrocław