ZeroHour

Vulnerabilities

3 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2020-6948
+1 in the same advisory: …6949
A remote code execution issue was discovered in HashBrown CMS through 1.3.3.

A remote code execution issue was discovered in HashBrown CMS through 1.3.3. Server/Entity/Deployer/GitDeployer.js has a Service.AppService.exec call that mishandles the URL, repository, username, and password.

NVD description · AI analysis pending
9.8
group max
3% PoC
  • hashbrowncms hashbrown cms
CVE-2020-5840
An issue was discovered in HashBrown CMS before 1.3.2.

An issue was discovered in HashBrown CMS before 1.3.2. Server/Entity/Resource/Connection.js allows an attacker to reach a parent directory via a crafted name or ID field.

NVD description · AI analysis pending
7.51%
  • hashbrowncms hashbrown cms