Vulnerabilities
7 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-50565 | A cross-site scripting (XSS) vulnerability in the component /logs/dopost.html in RPCMS v3.5.5 allows attackers to execute arbitrary web scripts or HTML via a cr A cross-site scripting (XSS) vulnerability in the component /logs/dopost.html in RPCMS v3.5.5 allows attackers to execute arbitrary web scripts or HTML via a crafted payload. NVD description · AI analysis pending | 5.4 | <1% | PoC |
| — | |
| CVE-2022-41475 | RPCMS v3.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) which allows attackers to arbitrarily add an administrator account. RPCMS v3.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) which allows attackers to arbitrarily add an administrator account. NVD description · AI analysis pending | 8.8 group max | <1% | PoC |
| — | |
| CVE-2021-37394 | In RPCMS v1.8 and below, attackers can interact with API and change variable "role" to "admin" to achieve admin user registration. In RPCMS v1.8 and below, attackers can interact with API and change variable "role" to "admin" to achieve admin user registration. NVD description · AI analysis pending | 8.8 group max | 1% | PoC |
| — |