Hashbrowncms

Hashbrown Cms

5 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.59%
  • Veröffentlicht 05.08.2026 05:46:26
  • Zuletzt bearbeitet 10.08.2026 12:17:23

HashBrown CMS through 1.4.6 contains an OS Command Injection vulnerability (CWE-78) in the Git deployer component. GitDeployer.pullRepo in src/Server/Entity/Deployer/GitDeployer.js executes AppService.exec, interpolating the configured branch value d...

  • EPSS 0.97%
  • Veröffentlicht 05.08.2026 05:46:19
  • Zuletzt bearbeitet 10.08.2026 12:17:23

HashBrown CMS through 1.4.6 contains an OS Command Injection vulnerability (CWE-78) in the media upload thumbnail generation routine. Media.generateThumbnail in src/Server/Entity/Resource/Media.js builds a temporary file path as 'thumbnail' + Path.ex...

Exploit
  • EPSS 3.57%
  • Veröffentlicht 13.01.2020 19:15:12
  • Zuletzt bearbeitet 21.11.2024 05:36:22

A remote code execution issue was discovered in HashBrown CMS through 1.3.3. Server/Entity/Deployer/GitDeployer.js has a Service.AppService.exec call that mishandles the URL, repository, username, and password.

Exploit
  • EPSS 1.28%
  • Veröffentlicht 13.01.2020 19:15:12
  • Zuletzt bearbeitet 21.11.2024 05:36:22

A privilege escalation issue was discovered in the postUser function in HashBrown CMS through 1.3.3. An editor user can change the password hash of an admin user's account, or otherwise reconfigure that account.

  • EPSS 1.49%
  • Veröffentlicht 06.01.2020 18:15:24
  • Zuletzt bearbeitet 21.11.2024 05:34:40

An issue was discovered in HashBrown CMS before 1.3.2. Server/Entity/Resource/Connection.js allows an attacker to reach a parent directory via a crafted name or ID field.