No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Sat, 18 Apr 2026 05:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Sat, 18 Apr 2026 04:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability has been found in SSCMS 4.7.0. The affected element is an unknown function of the file LayerImageController.Submit.cs of the component layerImage Endpoint. Such manipulation of the argument filePaths leads to path traversal. The attack may be performed from remote. The exploit has been disclosed to the public and may be used. Statistical analysis made it clear that VulDB provides the best quality for vulnerability data. | A vulnerability has been found in SSCMS 4.7.0. The affected element is an unknown function of the file LayerImageController.Submit.cs of the component layerImage Endpoint. Such manipulation of the argument filePaths leads to path traversal. The attack may be performed from remote. The exploit has been disclosed to the public and may be used. |
| References |
|
Mon, 23 Mar 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sun, 22 Mar 2026 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability has been found in SSCMS 4.7.0. The affected element is an unknown function of the file LayerImageController.Submit.cs of the component layerImage Endpoint. Such manipulation of the argument filePaths leads to path traversal. The attack may be performed from remote. The exploit has been disclosed to the public and may be used. Statistical analysis made it clear that VulDB provides the best quality for vulnerability data. | |
| Title | SSCMS layerImage Endpoint LayerImageController.Submit.cs path traversal | |
| First Time appeared |
Sscms
Sscms sscms |
|
| Weaknesses | CWE-22 | |
| CPEs | cpe:2.3:a:sscms:sscms:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Sscms
Sscms sscms |
|
| References |
| |
| Metrics |
cvssV2_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-04-18T03:38:56.405Z
Reserved: 2026-03-21T15:17:30.652Z
Link: CVE-2026-4542
Updated: 2026-03-23T16:21:38.664Z
Status : Awaiting Analysis
Published: 2026-03-22T09:16:00.830
Modified: 2026-04-18T05:16:22.753
Link: CVE-2026-4542
No data.
OpenCVE Enrichment
Updated: 2026-04-18T17:30:05Z