CVE-2018-25184 - Surreal ToDo 0.6.1.2 Local File Inclusion via index.php

CVE-2018-25184 - Surreal ToDo 0.6.1.2 Local File Inclusion via index.php

CVE ID : CVE-2018-25184 Published : March 6, 2026, 12:19 p.m. | 39 minutes ago Description : Surreal ToDo 0.6.1.2 contains a local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files by manipulating the content parameter. Attackers can supply directory traversal sequences through the content parameter in index.php to access sensitive system files like configuration and initialization files. Severity: 6.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE Details

Severity
MEDIUM
Published
March 6, 2026
Affected Product: php
Attack Vector: local