CVE-2024-24469
- EPSS 1.7%
- Veröffentlicht 05.02.2024 16:15:55
- Zuletzt bearbeitet 21.11.2024 08:59:18
Cross Site Request Forgery vulnerability in flusity-CMS v.2.33 allows a remote attacker to execute arbitrary code via the delete_post .php.
CVE-2024-24468
- EPSS 1.61%
- Veröffentlicht 05.02.2024 16:15:55
- Zuletzt bearbeitet 15.05.2025 20:15:46
Cross Site Request Forgery vulnerability in flusity-CMS v.2.33 allows a remote attacker to execute arbitrary code via the add_customblock.php.
CVE-2024-24470
- EPSS 0.78%
- Veröffentlicht 02.02.2024 16:15:55
- Zuletzt bearbeitet 21.11.2024 08:59:18
Cross Site Request Forgery vulnerability in flusity-CMS v.2.33 allows a remote attacker to execute arbitrary code via the update_post.php component.
CVE-2024-24524
- EPSS 1.64%
- Veröffentlicht 02.02.2024 08:15:46
- Zuletzt bearbeitet 21.11.2024 08:59:22
Cross Site Request Forgery (CSRF) vulnerability in flusity-CMS v.2.33, allows remote attackers to execute arbitrary code via the add_menu.php component.
CVE-2023-5812
- EPSS 0.06%
- Veröffentlicht 27.10.2023 02:15:07
- Zuletzt bearbeitet 21.11.2024 08:42:32
A vulnerability has been found in flusity CMS and classified as critical. Affected by this vulnerability is the function handleFileUpload of the file core/tools/upload.php. The manipulation of the argument uploaded_file leads to unrestricted upload. ...
CVE-2023-5811
- EPSS 0.06%
- Veröffentlicht 27.10.2023 01:15:32
- Zuletzt bearbeitet 21.11.2024 08:42:32
A vulnerability, which was classified as problematic, was found in flusity CMS. Affected is the function loadPostAddForm of the file core/tools/posts.php. The manipulation of the argument menu_id leads to cross site scripting. It is possible to launc...
CVE-2023-5810
- EPSS 0.06%
- Veröffentlicht 27.10.2023 01:15:32
- Zuletzt bearbeitet 21.11.2024 08:42:32
A vulnerability, which was classified as problematic, has been found in flusity CMS. This issue affects the function loadPostAddForm of the file core/tools/posts.php. The manipulation of the argument edit_post_id leads to cross site scripting. The at...
CVE-2023-5793
- EPSS 0.06%
- Veröffentlicht 26.10.2023 18:15:08
- Zuletzt bearbeitet 29.01.2026 14:45:47
A vulnerability was found in flusity CMS and classified as problematic. This issue affects the function loadCustomBlocCreateForm of the file /core/tools/customblock.php of the component Dashboard. The manipulation of the argument customblock_place le...