CVE-2018-9850: Gxlcms Qy

High severity, CVSS 7.5. EPSS: 1.8% chance of exploitation in the next 30 days.

In Gxlcms QY v1.0.0713, Lib\Lib\Action\Admin\DataAction.class.php allows remote attackers to delete any file via directory traversal sequences in the id parameter of an Admin-Data-del request.

Affected products

  • Gxlcms Gxlcms Qy: version 1.0.0713 only

Published 2018-04-08. Last modified 2026-06-17.