CVE-2023-46990
- EPSS 1.32%
- Veröffentlicht 20.11.2023 20:15:07
- Zuletzt bearbeitet 21.11.2024 08:29:36
Deserialization of Untrusted Data in PublicCMS v.4.0.202302.e allows a remote attacker to execute arbitrary code via a crafted script to the writeReplace function.
CVE-2023-48204
- EPSS 0.08%
- Veröffentlicht 16.11.2023 00:15:06
- Zuletzt bearbeitet 21.11.2024 08:31:12
An issue in PublicCMS v.4.0.202302.e allows a remote attacker to obtain sensitive information via the appToken and Parameters parameter of the api/method/getHtml component.
CVE-2023-34852
- EPSS 0.39%
- Veröffentlicht 15.06.2023 20:15:09
- Zuletzt bearbeitet 18.12.2024 17:15:11
PublicCMS <=V4.0.202302 is vulnerable to Insecure Permissions.
CVE-2020-20914
- EPSS 1.17%
- Veröffentlicht 04.04.2023 15:15:08
- Zuletzt bearbeitet 14.02.2025 16:15:31
SQL Injection vulnerability found in San Luan PublicCMS v.4.0 allows a remote attacker to execute arbitrary code via the sql parameter.
CVE-2020-20915
- EPSS 1.17%
- Veröffentlicht 04.04.2023 15:15:08
- Zuletzt bearbeitet 14.02.2025 17:15:11
SQL Injection vulnerability found in PublicCMS v.4.0 allows a remote attacker to execute arbitrary code via sql parameter of the the SysSiteAdminControl.
CVE-2022-3950
- EPSS 0.21%
- Veröffentlicht 11.11.2022 14:15:10
- Zuletzt bearbeitet 21.11.2024 07:20:35
A vulnerability, which was classified as problematic, was found in sanluan PublicCMS. Affected is the function initLink of the file dwz.min.js of the component Tab Handler. The manipulation leads to cross site scripting. It is possible to launch the ...
CVE-2021-27693
- EPSS 0.32%
- Veröffentlicht 02.09.2022 18:15:11
- Zuletzt bearbeitet 21.11.2024 05:58:26
Server-side Request Forgery (SSRF) vulnerability in PublicCMS before 4.0.202011.b via /publiccms/admin/ueditor when the action is catchimage.
CVE-2022-29784
- EPSS 0.23%
- Veröffentlicht 03.06.2022 21:15:08
- Zuletzt bearbeitet 21.11.2024 06:59:41
PublicCMS V4.0.202204.a and below contains an information leak via the component /views/directive/sys/SysConfigDataDirective.java.
CVE-2022-23389
- EPSS 3.93%
- Veröffentlicht 14.02.2022 21:15:09
- Zuletzt bearbeitet 21.11.2024 06:48:29
PublicCMS v4.0 was discovered to contain a remote code execution (RCE) vulnerability via the cmdarray parameter.
CVE-2021-40881
- EPSS 0.85%
- Veröffentlicht 15.09.2021 22:15:11
- Zuletzt bearbeitet 21.11.2024 06:25:00
An issue in the BAT file parameters of PublicCMS v4.0 allows attackers to execute arbitrary code.