07fly

07flycms

10 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.05%
  • Veröffentlicht 06.07.2025 08:32:05
  • Zuletzt bearbeitet 01.08.2025 22:28:49

A vulnerability classified as problematic was found in 07FLYCMS, 07FLY-CMS and 07FlyCRM up to 1.3.9. This vulnerability affects unknown code. The manipulation leads to cross-site request forgery. The attack can be initiated remotely. The exploit has ...

  • EPSS 0.14%
  • Veröffentlicht 28.02.2025 23:15:10
  • Zuletzt bearbeitet 15.04.2025 20:10:40

Cross Site Request Forgery vulnerability in 07FLYCMS v.1.3.9 allows a remote attacker to execute arbitrary code via the id parameter of the del.html component.

Exploit
  • EPSS 0.04%
  • Veröffentlicht 16.01.2025 16:15:33
  • Zuletzt bearbeitet 15.04.2025 20:09:27

07FLYCMS V1.3.9 was discovered to contain a Cross-Site Request Forgery (CSRF) via admin/doAdminAction.php?act=editShop&shopId.

Exploit
  • EPSS 0.04%
  • Veröffentlicht 16.01.2025 16:15:32
  • Zuletzt bearbeitet 15.04.2025 20:09:13

07FLYCMS V1.3.9 was discovered to contain a Cross-Site Request Forgery (CSRF) via /erp.07fly.net:80/oa/OaWorkReport/add.html.

Exploit
  • EPSS 0.06%
  • Veröffentlicht 14.11.2024 22:15:20
  • Zuletzt bearbeitet 18.04.2025 02:30:05

07FLYCMS V1.3.9 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component 'erp.07fly.net:80/admin/SysNotifyUser/del.html?id=93'.

Exploit
  • EPSS 0.06%
  • Veröffentlicht 08.11.2024 21:15:20
  • Zuletzt bearbeitet 18.04.2025 02:27:59

07FLYCMS V1.3.9 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component http://erp.07fly.net:80/oa/OaSchedule/add.html.

Exploit
  • EPSS 0.29%
  • Veröffentlicht 13.10.2024 02:15:15
  • Zuletzt bearbeitet 30.07.2025 15:01:41

A vulnerability classified as critical was found in 07FLYCMS, 07FLY-CMS and 07FlyCRM up to 1.2.0. This vulnerability affects the function pictureUpload of the file /admin/File/pictureUpload. The manipulation of the argument file leads to unrestricted...

Exploit
  • EPSS 0.26%
  • Veröffentlicht 12.10.2024 23:15:11
  • Zuletzt bearbeitet 30.07.2025 15:16:43

A vulnerability classified as critical has been found in 07FLYCMS, 07FLY-CMS and 07FlyCRM up to 1.2.0. This affects the function fileUpload of the file /admin/File/fileUpload. The manipulation of the argument file leads to unrestricted upload. It is ...

Exploit
  • EPSS 0.26%
  • Veröffentlicht 11.10.2024 13:15:21
  • Zuletzt bearbeitet 30.07.2025 15:44:51

A vulnerability was found in 07FLYCMS, 07FLY-CMS and 07FlyCRM 1.3.8. It has been declared as critical. Affected by this vulnerability is the function uploadFile of the file /admin/SysModule/upload/ajaxmodel/upload/uploadfilepath/sysmodule_1 of the co...

Exploit
  • EPSS 0.1%
  • Veröffentlicht 11.10.2024 13:15:21
  • Zuletzt bearbeitet 30.07.2025 15:42:24

A vulnerability was found in 07FLYCMS, 07FLY-CMS and 07FlyCRM 1.3.8. It has been rated as problematic. Affected by this issue is some unknown functionality of the component System Settings Page. The manipulation of the argument Login Interface Copyri...