CVE-2018-10122: Chanzhi

High severity, CVSS 7.5. EPSS: 2.1% chance of exploitation in the next 30 days.

QingDao Nature Easy Soft Chanzhi Enterprise Portal System (aka chanzhieps) pro1.6 allows remote attackers to read arbitrary files via directory traversal sequences in the pathname parameter to www/file.php.

Affected products

  • Chanzhi Chanzhi: version pro1.6 only

Published 2018-04-16. Last modified 2026-06-17.