Filtered by vendor Flatcore Subscriptions
Total 23 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2021-23835 1 Flatcore 1 Flatcore 2024-08-03 4.9 Medium
An issue was discovered in flatCore before 2.0.0 build 139. A local file disclosure vulnerability was identified in the docs_file HTTP request body parameter for the acp interface. This can be exploited with admin access rights. The affected parameter (which retrieves the contents of the specified file) was found to be accepting malicious user input without proper sanitization, thus leading to retrieval of backend server sensitive files, e.g., /etc/passwd, SQLite database files, PHP source code, etc.
CVE-2021-3745 1 Flatcore 1 Flatcore-cms 2024-08-03 6.6 Medium
flatcore-cms is vulnerable to Unrestricted Upload of File with Dangerous Type
CVE-2022-43118 1 Flatcore 1 Flatcore-cms 2024-08-03 6.1 Medium
A cross-site scripting (XSS) vulnerability in flatCore-CMS v2.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Username text field.