CVE-2021-36545
- EPSS 0.18%
- Veröffentlicht 03.02.2023 18:15:11
- Zuletzt bearbeitet 26.03.2025 17:15:22
Cross Site Scripting (XSS) vulnerability in tpcms 3.2 allows remote attackers to run arbitrary code via the cfg_copyright or cfg_tel field in Site Configuration page.
CVE-2021-36544
- EPSS 0.28%
- Veröffentlicht 03.02.2023 18:15:10
- Zuletzt bearbeitet 26.03.2025 17:15:21
Incorrect Access Control issue discovered in tpcms 3.2 allows remote attackers to view sensitive information via path in application URL.
CVE-2022-29624
- EPSS 0.77%
- Veröffentlicht 02.06.2022 14:15:49
- Zuletzt bearbeitet 21.11.2024 06:59:27
An arbitrary file upload vulnerability in the Add File function of TPCMS v3.2 allows attackers to execute arbitrary code via a crafted PHP file.
CVE-2022-27442
- EPSS 0.27%
- Veröffentlicht 04.04.2022 21:15:08
- Zuletzt bearbeitet 21.11.2024 06:55:44
TPCMS v3.2 allows attackers to access the ThinkPHP log directory and obtain sensitive information such as the administrator's user name and password.
CVE-2022-27441
- EPSS 0.22%
- Veröffentlicht 04.04.2022 21:15:07
- Zuletzt bearbeitet 21.11.2024 06:55:44
A stored cross-site scripting (XSS) vulnerability in TPCMS v3.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Phone text box.