CVE-2018-18892 is a critical arbitrary PHP code execution vulnerability affecting MiniCMS 1.10. An unauthenticated attacker can exploit this by manipulating the sitename parameter during installation, leading to full compromise of the affected system. With a CVSS score of 9.8, this vulnerability is easily exploitable over the network with no user interaction required, resulting in high impact to confidentiality, integrity, and availability. While no public exploit code or active exploitation has been observed, and community discussion is minimal, the high severity warrants immediate patching for any MiniCMS 1.10 installations.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.10CPE matchmatch criteria | cpe:2.3:a:1234n:minicms:1.10:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.