Loading
Generated remediation guidance and an executive summary. No account required.
BuddyPress Xprofile Custom Fields Type 2.6.3 contains a remote code execution vulnerability that allows authenticated users to delete arbitrary files by manipulating unescaped POST parameters. Attackers can modify the field_hiddenfile and field_deleteimg parameters during profile editing to unlink files from the server.
No affected products information available.
Use CWE-22 to widen CVE-2018-25308 into its surrounding weakness, vendor, and product context.