Vulnerabilities
12 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2017-20064 | A vulnerability was found in Elefant CMS 1.3.12-RC. A vulnerability was found in Elefant CMS 1.3.12-RC. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /designer/add/layout. The manipulation leads to code injection. The attack can be launched remotely. Upgrading to version 1.3.13 is able to address this issue. It is recommended to upgrade the affected component. NVD description · AI analysis pending | 8.8 group max | 1% | PoC |
| — | |
| CVE-2017-20058 | A vulnerability classified as problematic was found in Elefant CMS 1.3.12-RC. A vulnerability classified as problematic was found in Elefant CMS 1.3.12-RC. Affected by this vulnerability is an unknown functionality of the component Version Comparison. The manipulation leads to basic cross site scripting (Persistent). The attack can be launched remotely. Upgrading to version 1.3.13 is able to address this issue. It is recommended to upgrade the affected component. NVD description · AI analysis pending | 6.1 | <1% | PoC |
| — | |
| CVE-2018-16975 +1 in the same advisory: …16974 | An issue was discovered in Elefant CMS before 2.0.7. An issue was discovered in Elefant CMS before 2.0.7. There is a PHP Code Execution Vulnerability in /designer/add/stylesheet.php by using a .php extension in the New Stylesheet Name field in conjunction with <?php content, because of insufficient input validation in apps/designer/handlers/csspreview.php. NVD description · AI analysis pending | 9.8 | 4% | PoC |
| — | |
| CVE-2018-16387 | An issue was discovered in Elefant CMS before 2.0.5. An issue was discovered in Elefant CMS before 2.0.5. There is a CSRF vulnerability that can add an account via user/add. NVD description · AI analysis pending | 8.8 | <1% | PoC |
| — | |
| CVE-2018-15601 | apps/filemanager/handlers/upload/drop.php in Elefant CMS 2.0.3 performs a urldecode step too late in the "Cannot upload executable files" protection mechanism. apps/filemanager/handlers/upload/drop.php in Elefant CMS 2.0.3 performs a urldecode step too late in the "Cannot upload executable files" protection mechanism. NVD description · AI analysis pending | 9.8 | 2% |
| — |