ZeroHour

Vulnerabilities

8 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2021-43736
+1 in the same advisory: …43735
CmsWing CMS 1.3.7 is affected by a Remote Code Execution (RCE) vulnerability via parameter:

CmsWing CMS 1.3.7 is affected by a Remote Code Execution (RCE) vulnerability via parameter: log rule

NVD description · AI analysis pending
9.82% PoC
  • cmswing cmswing
CVE-2020-24992
+1 in the same advisory: …24993
There is a cross site scripting vulnerability on CmsWing 1.3.7.

There is a cross site scripting vulnerability on CmsWing 1.3.7. This vulnerability (stored XSS) is triggered when an administrator accesses the content management module.

NVD description · AI analysis pending
5.4<1% PoC
  • cmswing cmswing
CVE-2020-20294
+2 in the same advisory: …20295 …20296
An issue was found in CMSWing project version 1.3.8.

An issue was found in CMSWing project version 1.3.8. Because the log function does not check the log parameter, malicious parameters can execute arbitrary commands.

NVD description · AI analysis pending
9.82% PoC
  • cmswing cmswing
CVE-2019-7649
global.encryptPassword in bootstrap/global.js in CMSWing 1.3.7 relies on multiple MD5 operations for password hashing.

global.encryptPassword in bootstrap/global.js in CMSWing 1.3.7 relies on multiple MD5 operations for password hashing.

NVD description · AI analysis pending
7.5<1% PoC
  • cmswing cmswing