CVE-2023-43878
- EPSS 0.29%
- Veröffentlicht 28.09.2023 15:15:12
- Zuletzt bearbeitet 21.11.2024 08:24:57
Rite CMS 3.0 has Multiple Cross-Site scripting (XSS) vulnerabilities that allow attackers to execute arbitrary code via a crafted payload into the Main Menu Items in the Administration Menu.
CVE-2022-24248
- EPSS 1.01%
- Veröffentlicht 12.04.2022 12:15:08
- Zuletzt bearbeitet 21.11.2024 06:50:02
RiteCMS version 3.1.0 and below suffers from an arbitrary file deletion via path traversal vulnerability in Admin Panel. Exploiting the vulnerability allows an authenticated attacker to delete any file in the web root (along with any other file on th...
CVE-2022-24247
- EPSS 1.47%
- Veröffentlicht 12.04.2022 12:15:08
- Zuletzt bearbeitet 21.11.2024 06:50:02
RiteCMS version 3.1.0 and below suffers from an arbitrary file overwrite via path traversal vulnerability in Admin Panel. Exploiting the vulnerability allows an authenticated attacker to overwrite any file in the web root (along with any other file o...
- EPSS 24.71%
- Veröffentlicht 08.04.2022 12:15:08
- Zuletzt bearbeitet 21.11.2024 06:33:59
RiteCMS version 3.1.0 and below suffers from a remote code execution vulnerability in the admin panel. An authenticated attacker can upload a PHP file and bypass the .htacess configuration to deny execution of .php files in media and files directory ...
- EPSS 28.62%
- Veröffentlicht 18.08.2020 21:15:12
- Zuletzt bearbeitet 21.11.2024 05:14:14
An issue was discovered in RiteCMS 2.2.1. An authenticated user can directly execute system commands by uploading a php web shell in the "Filemanager" section.
CVE-2013-5317
- EPSS 0.41%
- Veröffentlicht 20.08.2013 14:55:46
- Zuletzt bearbeitet 11.04.2025 00:51:21
Cross-site scripting (XSS) vulnerability in RiteCMS 1.0.0 allows remote authenticated users to inject arbitrary web script or HTML via the mode parameter to cms/index.php.
CVE-2013-5316
- EPSS 0.26%
- Veröffentlicht 20.08.2013 14:55:21
- Zuletzt bearbeitet 11.04.2025 00:51:21
Cross-site request forgery (CSRF) vulnerability in RiteCMS 1.0.0 allows remote attackers to hijack the authentication of administrators for requests that change the administrator password via an edit user action to cms/index.php.