CVE-2022-45535
- EPSS 0.08%
- Veröffentlicht 22.11.2022 21:15:11
- Zuletzt bearbeitet 25.04.2025 21:15:36
AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability via the edit parameter at \admin\categories.php. This vulnerability allows attackers to access database information.
CVE-2022-45529
- EPSS 0.08%
- Veröffentlicht 22.11.2022 21:15:11
- Zuletzt bearbeitet 25.04.2025 21:15:35
AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability via the post_category_id parameter at \admin\includes\edit_post.php. This vulnerability allows attackers to access database information.
CVE-2022-45331
- EPSS 0.11%
- Veröffentlicht 22.11.2022 21:15:10
- Zuletzt bearbeitet 25.04.2025 21:15:35
AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability via the p_id parameter at \post.php. This vulnerability allows attackers to access database information.
CVE-2022-45330
- EPSS 0.11%
- Veröffentlicht 22.11.2022 21:15:10
- Zuletzt bearbeitet 25.04.2025 21:15:35
AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability via the Category parameter at \category.php. This vulnerability allows attackers to access database information.
CVE-2022-38305
- EPSS 0.74%
- Veröffentlicht 13.09.2022 23:15:08
- Zuletzt bearbeitet 21.11.2024 07:16:13
AeroCMS v0.0.1 was discovered to contain an arbitrary file upload vulnerability via the component /admin/profile.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.
CVE-2022-38812
- EPSS 0.23%
- Veröffentlicht 31.08.2022 18:15:08
- Zuletzt bearbeitet 21.11.2024 07:17:07
AeroCMS 0.1.1 is vulnerable to SQL Injection via the author parameter.
CVE-2022-27061
- EPSS 3.08%
- Veröffentlicht 08.04.2022 09:15:11
- Zuletzt bearbeitet 21.11.2024 06:55:03
AeroCMS v0.0.1 was discovered to contain an arbitrary file upload vulnerability via the Post Image function under the Admin panel. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.
CVE-2022-27063
- EPSS 0.7%
- Veröffentlicht 08.04.2022 09:15:11
- Zuletzt bearbeitet 21.11.2024 06:55:03
AeroCMS v0.0.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability via view_all_comments.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Comments text f...
CVE-2022-27062
- EPSS 0.68%
- Veröffentlicht 08.04.2022 09:15:11
- Zuletzt bearbeitet 21.11.2024 06:55:03
AeroCMS v0.0.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability via add_post.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Post Title text field.