Surreal ToDo 0.6.1.2 contains a local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files by manipulating the content parameter. Attackers can supply directory traversal sequences through the content parameter in index.php to access sensitive system files like configuration and initialization files.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-03-06 13:16
Updated : 2026-06-17 01:54
NVD link : CVE-2018-25184
Mitre link : CVE-2018-25184
CVE.ORG link : CVE-2018-25184
JSON object : View
Products Affected
No product.
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
