S4E just found a high top 10 tcp port service scan
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2018-13980 Scanner

CVE-2018-13980 scanner - Directory Traversal vulnerability in Zeta Producer Desktop CMS

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
0
Times Used
by S4E users
0
Assets Scanned
domains & IPs
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2018-13980
5.5
CVSS

The websites that were built from Zeta Producer Desktop CMS before 14.2.1 are vulnerable to unauthenticated file disclosure if the plugin "filebrowser" is installed, because of assets/php/filebrowser/filebrowser.main.php?file=../ directory traversal.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

Zeta Producer Desktop CMS is a website building tool used by individuals and businesses alike. It offers users a range of features and options to create and manage their web presence, including drag-and-drop functionality, customizable templates, and more. However, a recent vulnerability has been detected in the software, which could have serious consequences for those using it.

The CVE-2018-13980 vulnerability has been identified in Zeta Producer Desktop CMS, specifically in the plugin "filebrowser". If this plugin is installed on a website built using the software before version 14.2.1, an attacker could easily gain access to sensitive files through directory traversal. This means that they could view and download files stored on the server, potentially exposing personal or confidential data.

If this vulnerability is exploited, it could lead to some serious consequences for website owners and their users. For example, personal information could be exposed, which could be used for identity theft or other malicious purposes. Additionally, confidential business data could be compromised, which could damage the reputation of the company and cause significant financial harm.

At S4E, we understand how important it is to keep your digital assets secure. That's why we offer a range of pro features, including vulnerability scanning and reporting, to help you stay on top of any potential threats. By signing up for our platform, you can rest assured that your website and its data are being monitored and protected around the clock. So why wait? Sign up today and see the difference for yourself!

 

REFERENCES

Solution Advice

To protect against this vulnerability, there are some simple precautions that website owners can take. These include:

  • Upgrading to the latest version of Zeta Producer Desktop CMS, which includes a fix for this vulnerability
  • Removing the "filebrowser" plugin from your website, unless absolutely necessary
  • Making sure that all other plugins and software used on your website are also up-to-date and patched against known vulnerabilities
  • Regularly backing up your website and its data, to ensure that you can recover quickly in the event of an attack
  • Monitoring your website for any suspicious activity, such as unauthorized file downloads or access attempts

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2018-13980 scanner - Directory Traversal vulnerability in Zeta Producer Desktop CMS S4E