CVE-2018-25178: RUL10 Easyndexer
High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.
Easyndexer 1.0 contains an arbitrary file download vulnerability that allows unauthenticated attackers to download sensitive files by manipulating the file parameter. Attackers can send POST requests to showtif.php with arbitrary file paths in the file parameter to retrieve system files like configuration and initialization files.
Affected products
- RUL10 Easyndexer: version 1.0 only
Published 2026-03-06. Last modified 2026-06-17.