CVE-2018-19228 is a directory traversal vulnerability affecting LAOBANCMS 2.0, allowing unauthenticated attackers to delete arbitrary files on the server. This high-severity flaw (CVSS 7.5) has a low attack complexity and no user interaction required, enabling impacts such as system reinstallation by deleting critical files like install/install.txt. While there is no evidence of active exploitation, public exploit code, or significant community discussion, its ease of exploitation poses a notable risk to unpatched systems.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.0CPE matchmatch criteria | cpe:2.3:a:laobancms:laobancms:2.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.