Loading
Directory traversal vulnerability in application/admin/controller/Main.php in NoneCms through 1.3.0 allows remote authenticated users to delete arbitrary files by leveraging back-office access to provide a ..\ in the param.path parameter.
Use CWE-22, 5none vendor hub and Nonecms product page to widen CVE-2018-6022 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2018-20062, CVE-2018-7219 and CVE-2020-18647 for nearby disclosures in the same product family.