CVE-2018-19329: Greencms
Medium severity, CVSS 4.9. EPSS: 1.8% chance of exploitation in the next 30 days.
GreenCMS v2.3.0603 allows remote authenticated administrators to delete arbitrary files by modifying a base64-encoded pathname in an m=admin&c=media&a=delfilehandle&id= call, related to the m=admin&c=media&a=restorefile delete button.
Affected products
- Greencms Greencms: version 2.3.0603 only
Published 2018-11-17. Last modified 2026-06-17.