๐Ÿ” CVE Alert

CVE-2018-25393

MEDIUM 6.5

Navigate CMS 2.8.5 Path Traversal via navigate_download.php

CVSS Score
6.5
EPSS Score
0.0%
EPSS Percentile
0th

Navigate CMS 2.8.5 contains a path traversal vulnerability that allows authenticated users to download arbitrary files by injecting directory traversal sequences in the id parameter. Attackers can send GET requests to navigate_download.php with path traversal payloads ../../../cfg/globals.php to access sensitive configuration files and system files outside the intended directory.

CWE CWE-22
Vendor navigatecms
Product navigate cms
Published May 29, 2026
Last Updated May 29, 2026
Stay Ahead of the Next One

Get instant alerts for navigatecms navigate cms

Be the first to know when new medium vulnerabilities affecting navigatecms navigate cms are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None

Affected Versions

Navigatecms / Navigate CMS
2.8.5

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
exploit-db.com: https://www.exploit-db.com/exploits/45615 navigatecms.com: https://www.navigatecms.com/ master.dl.sourceforge.net: http://master.dl.sourceforge.net/project/navigatecms/releases/navigate-2.8.5r1355.zip vulncheck.com: https://www.vulncheck.com/advisories/navigate-cms-path-traversal-via-navigate-download-php

Credits

Ihsan Sencan