A vulnerability classified as problematic has been found in puppyCMS up to 5.1. This affects an unknown part of the file /admin/settings.php. The manipulation of the argument site_name leads to cross site scripting. It is possible to initiate the attack remotely. The associated identifier of this vulnerability is VDB-210699.
oryginał ENCVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:NPuppycms
APPPuppycms≤ 5.1
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
Tagi
XSS
Powiązane podatności
CVE-2020-18890CRITICAL9.8PL ✓ten sam produkt
RCE w PuppyCMS v5.1 poprzez nieprawidłowe uprawnienia w functions.php
CVE-2020-18888HIGH7.5ten sam produkt
Arbitrary File Deletion vulnerability in puppyCMS v5.1 allows remote malicious attackers to delete the file/fo...
CVE-2020-18889MEDIUM6.5ten sam produkt
Cross Site Request Forgery (CSRF) vulnerability in puppyCMS v5.1 that can change the admin's password via /adm...
CVE-2018-15847MEDIUM6.1ten sam produkt
An issue was discovered in puppyCMS 5.1. There is an XSS vulnerability via menu.php in the "Add Page/URL" URL ...