CVE-2017-11723: Xinha

High severity, CVSS 7.5. EPSS: 2.6% chance of exploitation in the next 30 days.

Directory traversal vulnerability in plugins/ImageManager/backend.php in Xinha 0.96, as used in Jojo 4.4.0, allows remote attackers to delete any folder via directory traversal sequences in the deld parameter.

Affected products

  • Xinha Xinha: version 0.96 only

Published 2017-07-29. Last modified 2026-06-17.