RSS   Vulnerabilities for 'Puppycms'   RSS

2021-05-06
 
CVE-2020-18888

CWE-862
 

 
Arbitrary File Deletion vulnerability in puppyCMS v5.1 allows remote malicious attackers to delete the file/folder via /admin/functions.php.

 
 
CVE-2020-18890

CWE-281
 

 
Rmote Code Execution (RCE) vulnerability in puppyCMS v5.1 due to insecure permissions, which could let a remote malicious user getshell via /admin/functions.php.

 
 
CVE-2020-18889

CWE-352
 

 
Cross Site Request Forgery (CSRF) vulnerability in puppyCMS v5.1 that can change the admin's password via /admin/settings.php.

 
2018-08-25
 
CVE-2018-15847

CWE-79
 

 
An issue was discovered in puppyCMS 5.1. There is an XSS vulnerability via menu.php in the "Add Page/URL" URL link field.

 


Copyright 2024, cxsecurity.com

 

Back to Top