Search Results (Refine Search)
- Results Type: Overview
- Keyword (text search): cpe:2.3:a:flatcore:flatcore-cms:1.4.6:*:*:*:*:*:*:*
- CPE Name Search: true
Vuln ID | Summary | CVSS Severity |
---|---|---|
CVE-2021-3745 |
flatcore-cms is vulnerable to Unrestricted Upload of File with Dangerous Type Published: October 28, 2021; 1:15:07 PM -0400 |
V4.0:(not available) V3.1: 6.6 MEDIUM V2.0: 6.0 MEDIUM |
CVE-2017-1000428 |
flatCore-CMS 1.4.6 is vulnerable to reflected XSS in user_management.php due to the use of $_SERVER['PHP_SELF'] to build links and a stored XSS in the admin log panel by specifying a malformed User-Agent string. Published: January 09, 2018; 9:29:31 PM -0500 |
V4.0:(not available) V3.0: 6.1 MEDIUM V2.0: 4.3 MEDIUM |
CVE-2017-7879 |
SQL Injection vulnerability in flatCore version 1.4.6 allows an attacker to read the content database. Published: April 14, 2017; 2:59:01 PM -0400 |
V4.0:(not available) V3.0: 7.5 HIGH V2.0: 5.0 MEDIUM |
CVE-2017-7878 |
SQL Injection vulnerability in flatCore version 1.4.6 allows an attacker to read and write to the users database. Published: April 14, 2017; 2:59:01 PM -0400 |
V4.0:(not available) V3.0: 9.8 CRITICAL V2.0: 7.5 HIGH |
CVE-2017-7877 |
CSRF vulnerability in flatCore version 1.4.6 allows remote attackers to modify CMS configurations. Published: April 14, 2017; 2:59:01 PM -0400 |
V4.0:(not available) V3.0: 8.8 HIGH V2.0: 6.8 MEDIUM |