CVE-2024-40550
- EPSS 0.62%
- Veröffentlicht 12.07.2024 16:15:05
- Zuletzt bearbeitet 21.11.2024 09:31:18
An arbitrary file upload vulnerability in the component /admin/cmsTemplate/savePlaceMetaData of Public CMS v.4.0.202302.e allows attackers to execute arbitrary code via uploading a crafted file.
CVE-2024-40549
- EPSS 0.31%
- Veröffentlicht 12.07.2024 16:15:05
- Zuletzt bearbeitet 25.03.2025 17:15:58
An arbitrary file upload vulnerability in the component /admin/cmsTemplate/savePlace of PublicCMS v4.0.202302.e allows attackers to execute arbitrary code via uploading a crafted file.
CVE-2024-40548
- EPSS 0.32%
- Veröffentlicht 12.07.2024 16:15:05
- Zuletzt bearbeitet 21.11.2024 09:31:18
An arbitrary file upload vulnerability in the component /admin/cmsTemplate/save of PublicCMS v4.0.202302.e allows attackers to execute arbitrary code via uploading a crafted file.
CVE-2024-40547
- EPSS 0.18%
- Veröffentlicht 12.07.2024 16:15:05
- Zuletzt bearbeitet 13.03.2025 13:15:41
PublicCMS v4.0.202302.e was discovered to contain an arbitrary file content replacement vulnerability via the component /admin/cmsTemplate/replace.
CVE-2024-40545
- EPSS 0.18%
- Veröffentlicht 12.07.2024 16:15:05
- Zuletzt bearbeitet 21.11.2024 09:31:17
An arbitrary file upload vulnerability in the component /admin/cmsWebFile/doUpload of PublicCMS v4.0.202302.e allows attackers to execute arbitrary code via uploading a crafted file.
CVE-2024-40544
- EPSS 0.26%
- Veröffentlicht 12.07.2024 16:15:05
- Zuletzt bearbeitet 26.03.2025 16:15:20
PublicCMS v4.0.202302.e was discovered to contain a Server-Side Request Forgery (SSRF) via the component /admin/#maintenance_sysTask/edit.
CVE-2024-40543
- EPSS 0.24%
- Veröffentlicht 12.07.2024 16:15:05
- Zuletzt bearbeitet 21.11.2024 09:31:17
PublicCMS v4.0.202302.e was discovered to contain a Server-Side Request Forgery (SSRF) via the component /admin/ueditor?action=catchimage.
CVE-2024-31759
- EPSS 0.18%
- Veröffentlicht 16.04.2024 23:15:09
- Zuletzt bearbeitet 12.06.2025 23:43:02
An issue in sanluan PublicCMS v.4.0.202302.e allows an attacker to escalate privileges via the change password function.
CVE-2024-2911
- EPSS 0.11%
- Veröffentlicht 26.03.2024 22:15:07
- Zuletzt bearbeitet 21.08.2025 17:45:20
A vulnerability, which was classified as problematic, was found in Tianjin PubliCMS 4.0.202302.e. This affects an unknown part. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely. The exploit has been...
CVE-2023-51252
- EPSS 0.17%
- Veröffentlicht 10.01.2024 09:15:44
- Zuletzt bearbeitet 20.06.2025 16:15:26
PublicCMS 4.0 is vulnerable to Cross Site Scripting (XSS). Because files can be uploaded and online preview function is provided, pdf files and html files containing malicious code are uploaded, an XSS popup window is realized through online viewing.