CVE-2018-6881: Dedecms
Medium severity, CVSS 5.3. EPSS: 2.2% chance of exploitation in the next 30 days.
EmpireCMS 6.6 allows remote attackers to discover the full path via an array value for a parameter to admin/tool/ShowPic.php.
Affected products
- Dedecms Dedecms: version 5.7 only
- Phome Empirecms: version 6.6 only; version 7.0 only; version 7.2 only
Published 2018-02-12. Last modified 2026-06-17.