CVE-2022-25495
- EPSS 1.06%
- Veröffentlicht 15.03.2022 18:15:12
- Zuletzt bearbeitet 21.11.2024 06:52:17
The component /jquery_file_upload/server/php/index.php of CuppaCMS v1.0 allows attackers to upload arbitrary files and execute arbitrary code via a crafted PHP file.
CVE-2022-25498
- EPSS 11.52%
- Veröffentlicht 15.03.2022 18:15:12
- Zuletzt bearbeitet 21.11.2024 06:52:17
CuppaCMS v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the saveConfigData function in /classes/ajax/Functions.php.
CVE-2022-25497
- EPSS 6.74%
- Veröffentlicht 15.03.2022 18:15:12
- Zuletzt bearbeitet 21.11.2024 06:52:17
CuppaCMS v1.0 was discovered to contain an arbitrary file read via the copy function.
CVE-2022-25486
- EPSS 68.83%
- Veröffentlicht 15.03.2022 18:15:12
- Zuletzt bearbeitet 21.11.2024 06:52:15
CuppaCMS v1.0 was discovered to contain a local file inclusion via the url parameter in /alerts/alertConfigField.php.
CVE-2022-25485
- EPSS 37.63%
- Veröffentlicht 15.03.2022 18:15:12
- Zuletzt bearbeitet 21.11.2024 06:52:15
CuppaCMS v1.0 was discovered to contain a local file inclusion via the url parameter in /alerts/alertLightbox.php.
CVE-2022-25401
- EPSS 7.03%
- Veröffentlicht 24.02.2022 15:15:31
- Zuletzt bearbeitet 21.11.2024 06:52:07
The copy function of the file manager in Cuppa CMS v1.0 allows any file to be copied to the current directory, granting attackers read access to arbitrary files.
CVE-2022-24647
- EPSS 0.37%
- Veröffentlicht 10.02.2022 23:15:08
- Zuletzt bearbeitet 21.11.2024 06:50:47
Cuppa CMS v1.0 was discovered to contain an arbitrary file deletion vulnerability via the unlink() function.
CVE-2022-24266
- EPSS 59.04%
- Veröffentlicht 31.01.2022 22:15:07
- Zuletzt bearbeitet 21.11.2024 06:50:04
Cuppa CMS v1.0 was discovered to contain a SQL injection vulnerability in /administrator/components/table_manager/ via the order_by parameter.
CVE-2022-24265
- EPSS 54.72%
- Veröffentlicht 31.01.2022 22:15:07
- Zuletzt bearbeitet 21.11.2024 06:50:04
Cuppa CMS v1.0 was discovered to contain a SQL injection vulnerability in /administrator/components/menu/ via the path=component/menu/&menu_filter=3 parameter.
CVE-2022-24264
- EPSS 63.62%
- Veröffentlicht 31.01.2022 22:15:07
- Zuletzt bearbeitet 21.11.2024 06:50:04
Cuppa CMS v1.0 was discovered to contain a SQL injection vulnerability in /administrator/components/table_manager/ via the search_word parameter.