CVE-2018-18487 affects Gxlcms v2.0, where a critical flaw in the database backup filename generation allows for predictable backup file locations due to the unsafe use of mt_rand(). This vulnerability carries a CVSS v3.0 score of 7.5 (HIGH), indicating a high-impact information disclosure risk that can be exploited remotely with low attack complexity and no user interaction required. While no active exploits, Metasploit modules, or ExploitDB entries are publicly known, and community discussion is minimal, the potential for unauthorized access to sensitive database backups remains a significant concern.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.0CPE matchmatch criteria | cpe:2.3:a:gxlcms:gxlcms:2.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.