ZeroHour

Vulnerabilities

11 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-57099
+1 in the same advisory: …57097
ClassCMS v4.8 has a code execution vulnerability.

ClassCMS v4.8 has a code execution vulnerability. Attackers can exploit this vulnerability by constructing a payload in the classview parameter of the model management feature, allowing them to execute arbitrary code and potentially take control of the server.

NVD description · AI analysis pending
9.8
group max
<1% PoC
  • classcms classcms
CVE-2024-12666
A vulnerability has been found in ClassCMS up to 4.8 and classified as critical.

A vulnerability has been found in ClassCMS up to 4.8 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin?do=admin:user:editPost of the component User Management Page. The manipulation leads to improper handling of insufficient privileges. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

NVD description · AI analysis pending
5.1<1% PoC
  • classcms classcms
CVE-2024-12503
A vulnerability classified as problematic was found in ClassCMS 4.8.

A vulnerability classified as problematic was found in ClassCMS 4.8. Affected by this vulnerability is an unknown functionality of the file /index.php/admin of the component Model Management Page. The manipulation of the argument URL leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

NVD description · AI analysis pending
5.1<1% PoC
  • classcms classcms
CVE-2024-48180
ClassCMS <=4.8 is vulnerable to file inclusion in the nowView method in/class/cms/cms.php, which can include a file uploaded to the/class/template directory to

ClassCMS <=4.8 is vulnerable to file inclusion in the nowView method in/class/cms/cms.php, which can include a file uploaded to the/class/template directory to execute PHP code.

NVD description · AI analysis pending
9.8<1%
  • classcms classcms
CVE-2024-8144
+1 in the same advisory: …8145
A vulnerability classified as problematic was found in ClassCMS 4.8.

A vulnerability classified as problematic was found in ClassCMS 4.8. Affected by this vulnerability is an unknown functionality of the file /index.php/admin of the component Logo Handler. The manipulation leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

NVD description · AI analysis pending
5.3
group max
<1% PoC
  • classcms classcms
CVE-2024-6932
A vulnerability was found in ClassCMS 4.5.

A vulnerability was found in ClassCMS 4.5. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /admin/?action=home&do=shop:index&keyword=&kind=all. The manipulation of the argument order leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-271987.

NVD description · AI analysis pending
5.3<1% PoC
  • classcms project classcms
CVE-2022-45966
here is an arbitrary file upload vulnerability in the file management function module of Classcms3.5.

here is an arbitrary file upload vulnerability in the file management function module of Classcms3.5.

NVD description · AI analysis pending
9.8<1% PoC
  • classcms project classcms
CVE-2022-25582
A stored cross-site scripting (XSS) vulnerability in the Column module of ClassCMS v2.5 and below allows attackers to execute arbitrary web scripts or HTML via

A stored cross-site scripting (XSS) vulnerability in the Column module of ClassCMS v2.5 and below allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Add Articles field.

NVD description · AI analysis pending
5.4<1% PoC
  • classcms project classcms
CVE-2022-25581
Classcms v2.5 and below contains an arbitrary file upload via the component \class\classupload.

Classcms v2.5 and below contains an arbitrary file upload via the component \class\classupload. This vulnerability allows attackers to execute code injection via a crafted .txt file.

NVD description · AI analysis pending
7.81% PoC
  • classcms classcms