Vulnerabilities
3 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2020-6948 +1 in the same advisory: …6949 | A remote code execution issue was discovered in HashBrown CMS through 1.3.3. A remote code execution issue was discovered in HashBrown CMS through 1.3.3. Server/Entity/Deployer/GitDeployer.js has a Service.AppService.exec call that mishandles the URL, repository, username, and password. NVD description · AI analysis pending | 9.8 group max | 3% | PoC |
| — | |
| CVE-2020-5840 | An issue was discovered in HashBrown CMS before 1.3.2. An issue was discovered in HashBrown CMS before 1.3.2. Server/Entity/Resource/Connection.js allows an attacker to reach a parent directory via a crafted name or ID field. NVD description · AI analysis pending | 7.5 | 1% |
| — |