Show filters
25 Total Results
Displaying 1-10 of 25
Sort by:
Attacker Value
Unknown
CVE-2024-57161
Disclosure Date: January 16, 2025 (last updated January 23, 2025)
07FLYCMS V1.3.9 was discovered to contain a Cross-Site Request Forgery (CSRF) via /erp.07fly.net:80/oa/OaWorkReport/edit.html
0
Attacker Value
Unknown
CVE-2024-57160
Disclosure Date: January 16, 2025 (last updated January 23, 2025)
07FLYCMS V1.3.9 was discovered to contain a Cross-Site Request Forgery (CSRF) via /erp.07fly.net:80/oa/OaTask/edit.html.
0
Attacker Value
Unknown
CVE-2024-9904
Disclosure Date: October 13, 2024 (last updated October 13, 2024)
A vulnerability classified as critical was found in 07FLYCMS, 07FLY-CMS and 07FlyCRM up to 1.2.0. This vulnerability affects the function pictureUpload of the file /admin/File/pictureUpload. The manipulation of the argument file leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The affected product is known with different names like 07FLYCMS, 07FLY-CMS, and 07FlyCRM. It was not possible to reach out to the vendor before assigning a CVE due to a not working mail address.
0
Attacker Value
Unknown
CVE-2024-9903
Disclosure Date: October 12, 2024 (last updated October 13, 2024)
A vulnerability classified as critical has been found in 07FLYCMS, 07FLY-CMS and 07FlyCRM up to 1.2.0. This affects the function fileUpload of the file /admin/File/fileUpload. The manipulation of the argument file leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The affected product is known with different names like 07FLYCMS, 07FLY-CMS, and 07FlyCRM. It was not possible to reach out to the vendor before assigning a CVE due to a not working mail address.
0
Attacker Value
Unknown
CVE-2024-9856
Disclosure Date: October 11, 2024 (last updated October 12, 2024)
A vulnerability was found in 07FLYCMS, 07FLY-CMS and 07FlyCRM 1.3.8. It has been rated as problematic. Affected by this issue is some unknown functionality of the component System Settings Page. The manipulation of the argument Login Interface Copyright leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The affected product is known with different names like 07FLYCMS, 07FLY-CMS, and 07FlyCRM. It was not possible to reach out to the vendor before assigning a CVE due to a not working mail address.
0
Attacker Value
Unknown
CVE-2024-9855
Disclosure Date: October 11, 2024 (last updated October 12, 2024)
A vulnerability was found in 07FLYCMS, 07FLY-CMS and 07FlyCRM 1.3.8. It has been declared as critical. Affected by this vulnerability is the function uploadFile of the file /admin/SysModule/upload/ajaxmodel/upload/uploadfilepath/sysmodule_1 of the component Module Plug-In Handler. The manipulation of the argument file leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The affected product is known with different names like 07FLYCMS, 07FLY-CMS, and 07FlyCRM. It was not possible to reach out to the vendor before assigning a CVE due to a not working mail address.
0
Attacker Value
Unknown
CVE-2024-22939
Disclosure Date: February 29, 2024 (last updated January 17, 2025)
Cross Site Request Forgery vulnerability in FlyCms v.1.0 allows a remote attacker to execute arbitrary code via the system/article/category_edit component.
0
Attacker Value
Unknown
CVE-2024-22819
Disclosure Date: January 18, 2024 (last updated January 24, 2024)
FlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerability via /system/email/email_templets_update.
0
Attacker Value
Unknown
CVE-2024-22818
Disclosure Date: January 18, 2024 (last updated January 24, 2024)
FlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerbility via /system/site/filterKeyword_save
0
Attacker Value
Unknown
CVE-2024-22817
Disclosure Date: January 18, 2024 (last updated January 24, 2024)
FlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerability via /system/email/email_conf_updagte
0