CVE-2019-16867: Hongcms Project Hongcms

Medium severity, CVSS 6.5. EPSS: 1.1% chance of exploitation in the next 30 days.

HongCMS 3.0.0 allows arbitrary file deletion via a ../ in the file parameter to admin/index.php/database/ajax?action=delete, a similar issue to CVE-2018-16774. (If the attacker deletes config.php and visits install/index.php, they can reinstall the product.)

Affected products

Published 2019-09-25. Last modified 2026-06-17.