CVE-2022-3464
- EPSS 0.3%
- Veröffentlicht 12.10.2022 10:15:09
- Zuletzt bearbeitet 21.11.2024 07:19:34
A vulnerability classified as problematic has been found in puppyCMS up to 5.1. This affects an unknown part of the file /admin/settings.php. The manipulation of the argument site_name leads to cross site scripting. It is possible to initiate the att...
CVE-2020-18888
- EPSS 0.16%
- Veröffentlicht 06.05.2021 18:15:07
- Zuletzt bearbeitet 21.11.2024 05:08:50
Arbitrary File Deletion vulnerability in puppyCMS v5.1 allows remote malicious attackers to delete the file/folder via /admin/functions.php.
CVE-2020-18890
- EPSS 0.64%
- Veröffentlicht 06.05.2021 18:15:07
- Zuletzt bearbeitet 21.11.2024 05:08:51
Rmote Code Execution (RCE) vulnerability in puppyCMS v5.1 due to insecure permissions, which could let a remote malicious user getshell via /admin/functions.php.
CVE-2020-18889
- EPSS 0.15%
- Veröffentlicht 06.05.2021 17:15:07
- Zuletzt bearbeitet 21.11.2024 05:08:50
Cross Site Request Forgery (CSRF) vulnerability in puppyCMS v5.1 that can change the admin's password via /admin/settings.php.
CVE-2018-15847
- EPSS 0.22%
- Veröffentlicht 25.08.2018 21:29:00
- Zuletzt bearbeitet 21.11.2024 03:51:33
An issue was discovered in puppyCMS 5.1. There is an XSS vulnerability via menu.php in the "Add Page/URL" URL link field.