
CVE-2018-25184 Surreal ToDo 0.6.1.2 contains a local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files by manipulating the content parameter… https://www.cve.org/CVERecord?id=CVE-2018-25184
Post summary
The text explains that Surreal ToDo 0.6.1.2 contains an LFI vulnerability permitting unauthenticated file reads via the content parameter, with no mention of exploits, patches, or active exploitation.
