Vulnerabilities
8 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2021-43736 +1 in the same advisory: …43735 | CmsWing CMS 1.3.7 is affected by a Remote Code Execution (RCE) vulnerability via parameter: CmsWing CMS 1.3.7 is affected by a Remote Code Execution (RCE) vulnerability via parameter: log rule NVD description · AI analysis pending | 9.8 | 2% | PoC |
| — | |
| CVE-2020-24992 +1 in the same advisory: …24993 | There is a cross site scripting vulnerability on CmsWing 1.3.7. There is a cross site scripting vulnerability on CmsWing 1.3.7. This vulnerability (stored XSS) is triggered when an administrator accesses the content management module. NVD description · AI analysis pending | 5.4 | <1% | PoC |
| — | |
| CVE-2020-20294 | An issue was found in CMSWing project version 1.3.8. An issue was found in CMSWing project version 1.3.8. Because the log function does not check the log parameter, malicious parameters can execute arbitrary commands. NVD description · AI analysis pending | 9.8 | 2% | PoC |
| — | |
| CVE-2019-7649 | global.encryptPassword in bootstrap/global.js in CMSWing 1.3.7 relies on multiple MD5 operations for password hashing. global.encryptPassword in bootstrap/global.js in CMSWing 1.3.7 relies on multiple MD5 operations for password hashing. NVD description · AI analysis pending | 7.5 | <1% | PoC |
| — |