CVE-2017-12586: Slims Akasia

Medium severity, CVSS 6.5. EPSS: 2.7% chance of exploitation in the next 30 days.

SLiMS 8 Akasia through 8.3.1 has an arbitrary file reading issue because of directory traversal in the url parameter to admin/help.php. It can be exploited by remote authenticated librarian users.

Affected products

  • Slims Akasia: version 8.0 only; version 8.1 only; version 8.2 only; version 8.3 only; version 8.3.1 only

Published 2017-08-06. Last modified 2026-06-17.