cmseasy V7.7.5_20211012 is affected by an arbitrary file write vulnerability. Through this vulnerability, a PHP script file is written to the website server, and accessing this file can lead to a code execution vulnerability.
oryginał ENCVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HCmseasy
APPCmseasy7.7.5_20211012
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
Tagi
RCEPath Traversal
CWE
Powiązane podatności
CVE-2023-34880CRITICAL9.8PL ✓ten sam produkt
CmsEasy — path traversal i wykonanie dowolnego kodu (RCE)
CVE-2024-34315HIGH7.5ten sam produkt
CmsEasy v7.7.7.9 was discovered to contain a local file inclusion vunerability via the file_get_contents funct...
CVE-2024-31551HIGH7.5ten sam produkt
Directory Traversal vulnerability in lib/admin/image.admin.php in cmseasy v7.7.7.9 20240105 allows attackers t...
CVE-2020-18406HIGH7.5ten sam produkt
An issue was discovered in cmseasy v7.0.0 that allows user credentials to be sent in clear text due to no encr...
CVE-2018-11679HIGH8.8ten sam produkt
An issue was discovered in CmsEasy 6.1_20180508. There is a CSRF vulnerability that can add an article via /in...