Filtered by vendor Puppycms
Subscribe
Total
5 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2022-3464 | 1 Puppycms | 1 Puppycms | 2024-02-28 | N/A | 6.1 MEDIUM |
A vulnerability classified as problematic has been found in puppyCMS up to 5.1. This affects an unknown part of the file /admin/settings.php. The manipulation of the argument site_name leads to cross site scripting. It is possible to initiate the attack remotely. The associated identifier of this vulnerability is VDB-210699. | |||||
CVE-2020-18889 | 1 Puppycms | 1 Puppycms | 2024-02-28 | 4.3 MEDIUM | 6.5 MEDIUM |
Cross Site Request Forgery (CSRF) vulnerability in puppyCMS v5.1 that can change the admin's password via /admin/settings.php. | |||||
CVE-2020-18888 | 1 Puppycms | 1 Puppycms | 2024-02-28 | 5.0 MEDIUM | 7.5 HIGH |
Arbitrary File Deletion vulnerability in puppyCMS v5.1 allows remote malicious attackers to delete the file/folder via /admin/functions.php. | |||||
CVE-2020-18890 | 1 Puppycms | 1 Puppycms | 2024-02-28 | 7.5 HIGH | 9.8 CRITICAL |
Rmote Code Execution (RCE) vulnerability in puppyCMS v5.1 due to insecure permissions, which could let a remote malicious user getshell via /admin/functions.php. | |||||
CVE-2018-15847 | 1 Puppycms | 1 Puppycms | 2024-02-28 | 4.3 MEDIUM | 6.1 MEDIUM |
An issue was discovered in puppyCMS 5.1. There is an XSS vulnerability via menu.php in the "Add Page/URL" URL link field. |