CVE-2021-41652
- EPSS 0.28%
- Veröffentlicht 01.03.2022 23:15:08
- Zuletzt bearbeitet 21.11.2024 06:26:35
Insecure permissions in the file database.sdb of BatFlat CMS v1.3.6 allows attackers to dump the entire database.
CVE-2021-27679
- EPSS 0.13%
- Veröffentlicht 11.03.2021 17:15:13
- Zuletzt bearbeitet 21.11.2024 05:58:25
Cross-site scripting (XSS) vulnerability in Navigation in Batflat CMS 1.3.6 allows remote attackers to inject arbitrary web script or HTML via the field name.
CVE-2021-27677
- EPSS 0.14%
- Veröffentlicht 11.03.2021 17:15:12
- Zuletzt bearbeitet 21.11.2024 05:58:25
Cross-site scripting (XSS) vulnerability in Galleries in Batflat CMS 1.3.6 allows remote attackers to inject arbitrary web script or HTML via the field name.
CVE-2021-27678
- EPSS 0.14%
- Veröffentlicht 11.03.2021 17:15:12
- Zuletzt bearbeitet 21.11.2024 05:58:25
Cross-site scripting (XSS) vulnerability in Snippets in Batflat CMS 1.3.6 allows remote attackers to inject arbitrary web script or HTML via the field name.
CVE-2020-35734
- EPSS 5.03%
- Veröffentlicht 15.02.2021 21:15:13
- Zuletzt bearbeitet 21.11.2024 05:27:58
Sruu.pl in Batflat 1.3.6 allows an authenticated user to perform code injection (and consequently Remote Code Execution) via the input fields of the Users tab. To exploit this, one must login to the administration panel and edit an arbitrary user's d...