CVE-2023-0651

A vulnerability was found in FastCMS 0.1.0. It has been classified as critical. Affected is an unknown function of the component Template Management. The manipulation leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Configurations

Configuration 1 (hide)

cpe:2.3:a:fastcms_project:fastcms:0.1.0:*:*:*:*:*:*:*

History

21 Nov 2024, 07:37

Type Values Removed Values Added
References () https://github.com/linmoren/fastcms_bug/blob/main/password.zip - Broken Link () https://github.com/linmoren/fastcms_bug/blob/main/password.zip - Broken Link
References () https://github.com/linmoren/fastcms_bug/blob/main/template_files_upload.md - Broken Link () https://github.com/linmoren/fastcms_bug/blob/main/template_files_upload.md - Broken Link
References () https://vuldb.com/?ctiid.220038 - Permissions Required, Third Party Advisory () https://vuldb.com/?ctiid.220038 - Permissions Required, Third Party Advisory
References () https://vuldb.com/?id.220038 - Third Party Advisory () https://vuldb.com/?id.220038 - Third Party Advisory
CVSS v2 : 6.5
v3 : 9.8
v2 : 6.5
v3 : 6.3

12 Sep 2024, 20:15

Type Values Removed Values Added
Summary (en) A vulnerability was found in FastCMS 0.1.0. It has been classified as critical. Affected is an unknown function of the component Template Management. The manipulation leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-220038 is the identifier assigned to this vulnerability. (en) A vulnerability was found in FastCMS 0.1.0. It has been classified as critical. Affected is an unknown function of the component Template Management. The manipulation leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
References
  • () https://vuldb.com/?submit.82316 -

Information

Published : 2023-02-02 16:19

Updated : 2024-11-21 07:37


NVD link : CVE-2023-0651

Mitre link : CVE-2023-0651

CVE.ORG link : CVE-2023-0651


JSON object : View

Products Affected

fastcms_project

  • fastcms
CWE
CWE-434

Unrestricted Upload of File with Dangerous Type