Filtered by vendor Flatcore
Subscriptions
Total
23 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2021-23835 | 1 Flatcore | 1 Flatcore | 2024-08-03 | 4.9 Medium |
An issue was discovered in flatCore before 2.0.0 build 139. A local file disclosure vulnerability was identified in the docs_file HTTP request body parameter for the acp interface. This can be exploited with admin access rights. The affected parameter (which retrieves the contents of the specified file) was found to be accepting malicious user input without proper sanitization, thus leading to retrieval of backend server sensitive files, e.g., /etc/passwd, SQLite database files, PHP source code, etc. | ||||
CVE-2021-3745 | 1 Flatcore | 1 Flatcore-cms | 2024-08-03 | 6.6 Medium |
flatcore-cms is vulnerable to Unrestricted Upload of File with Dangerous Type | ||||
CVE-2022-43118 | 1 Flatcore | 1 Flatcore-cms | 2024-08-03 | 6.1 Medium |
A cross-site scripting (XSS) vulnerability in flatCore-CMS v2.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Username text field. |