S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2023-27179 Scanner

Detects 'Arbitrary File Download' vulnerability in GDidees CMS affects v. 3.9.1 and lower.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3k
Times Used
continuous scan runs
5.5k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2023-27179
7.5
CVSShigh
Exploitable remotely over the internet · no authentication required.

GDidees CMS v3.9.1 and lower was discovered to contain an arbitrary file download vulenrability via the filename parameter at /_admin/imgdownload.php.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
n/aby n/a
n/a
Updated Aug 22, 2026View on NVD →
Detail

GDidees CMS is a user-friendly content management system, widely used by web developers and organizations for creating and managing website content. It provides an easy-to-use interface for web designers and non-technical professionals to create, manage and publish web content with ease. With an extensive range of features, GDidees CMS enables users to create customized websites that meet their individual requirements. It is a popular choice for e-commerce businesses, government agencies, and educational institutions.

One of the vulnerabilities that was detected in earlier versions of GDidees CMS is the arbitrary file download vulnerability - CVE-2023-27179. This vulnerability allows attackers to access sensitive files on the website and steal valuable data. The vulnerability is caused by insufficient input validation in the filename parameter of the imgdownload.php function in the admin interface of the CMS. This vulnerability can lead to severe consequences, as attackers can gain access to confidential data of the organization, such as user credentials, financial data, and other sensitive information.

Exploitation of this vulnerability can lead to serious security problems, including identity theft, financial fraud, and loss of reputation. Attackers can take advantage of this vulnerability to upload malicious files, execute arbitrary code, and even take control of the website. Such attacks can result in extensive damage to the organization, including financial loss, legal and regulatory penalties, and loss of customer trust.

By using s4e.io platform's pro features, users can quickly and easily identify vulnerabilities in their digital assets. With our powerful and user-friendly scanning tools, users can detect and address security vulnerabilities, effectively minimizing the risk of cyber attacks. Our platform provides real-time insights and recommendations to help users maintain a strong defensive posture against cyber threats. Join our community today and protect your digital assets from potential cyber attacks.

 

REFERENCES

Solution Advice

To protect against this vulnerability, organizations must take necessary precautions to secure their web assets. Here's a list of the measures that can be taken to combat this vulnerability:

  • Keep the CMS software and plugins up-to-date
  • Disable unnecessary features and modules
  • Choose strong passwords for all user accounts
  • Use firewalls and intrusion detection tools
  • Regularly run vulnerability assessments and penetration tests

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.