CVE-2018-25184 MEDIUM

CVE-2018-25184: Surreal ToDo 0.6.1.2 Local File Inclusion via index.php

Vendor Getsurreal
Product Surreal ToDo
Weakness CWE-22 · Path traversal
Published March 6, 2026
Last update March 9, 2026

CVSS base score

6.9/10
Attack vector Local
Attack complexity Low
Privileges required None
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

What the vulnerability does

Description

Surreal ToDo 0.6.1.2 contains a local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files by manipulating the content parameter. Attackers can supply directory traversal sequences through the content parameter in index.php to access sensitive system files like configuration and initialization files.

Key dates

Disclosure timeline

March 6, 2026 CVE published
March 9, 2026 Record updated