Show filters
23 Total Results
Displaying 11-20 of 23
Sort by:
Attacker Value
Unknown
CVE-2021-23837
Disclosure Date: January 15, 2021 (last updated February 22, 2025)
An issue was discovered in flatCore before 2.0.0 build 139. A time-based blind SQL injection was identified in the selected_folder HTTP request body parameter for the acp interface. The affected parameter (which retrieves the file contents of the specified folder) was found to be accepting malicious user input without proper sanitization, thus leading to SQL injection. Database related information can be successfully retrieved.
0
Attacker Value
Unknown
CVE-2021-23838
Disclosure Date: January 15, 2021 (last updated February 22, 2025)
An issue was discovered in flatCore before 2.0.0 build 139. A reflected XSS vulnerability was identified in the media_filter HTTP request body parameter for the acp interface. The affected parameter accepts malicious client-side script without proper input sanitization. For example, a malicious user can leverage this vulnerability to steal cookies from a victim user and perform a session-hijacking attack, which may then lead to unauthorized access to the site.
0
Attacker Value
Unknown
CVE-2021-23836
Disclosure Date: January 15, 2021 (last updated February 22, 2025)
An issue was discovered in flatCore before 2.0.0 build 139. A stored XSS vulnerability was identified in the prefs_smtp_psw HTTP request body parameter for the acp interface. An admin user can inject malicious client-side script into the affected parameter without any form of input sanitization. The injected payload will be executed in the browser of a user whenever one visits the affected module page.
0
Attacker Value
Unknown
CVE-2020-17452
Disclosure Date: August 09, 2020 (last updated February 21, 2025)
flatCore before 1.5.7 allows upload and execution of a .php file by an admin.
0
Attacker Value
Unknown
CVE-2020-17451
Disclosure Date: August 09, 2020 (last updated February 21, 2025)
flatCore before 1.5.7 allows XSS by an admin via the acp/acp.php?tn=pages&sub=edit&editpage=1 page_linkname, page_title, page_content, or page_extracontent parameter, or the acp/acp.php?tn=system&sub=sys_pref prefs_pagename, prefs_pagetitle, or prefs_pagesubtitle parameter.
0
Attacker Value
Unknown
CVE-2019-13961
Disclosure Date: July 18, 2019 (last updated November 27, 2024)
A CSRF vulnerability was found in flatCore before 1.5, leading to the upload of arbitrary .php files via acp/core/files.upload-script.php.
0
Attacker Value
Unknown
CVE-2019-10652
Disclosure Date: March 30, 2019 (last updated November 27, 2024)
An issue was discovered in flatCore 1.4.7. acp/acp.php allows remote authenticated administrators to upload arbitrary .php files, related to the addons feature.
0
Attacker Value
Unknown
CVE-2017-1000428
Disclosure Date: January 10, 2018 (last updated November 26, 2024)
flatCore-CMS 1.4.6 is vulnerable to reflected XSS in user_management.php due to the use of $_SERVER['PHP_SELF'] to build links and a stored XSS in the admin log panel by specifying a malformed User-Agent string.
0
Attacker Value
Unknown
CVE-2017-9451
Disclosure Date: June 06, 2017 (last updated November 26, 2024)
Cross site scripting (XSS) vulnerability in pages.edit_form.php in flatCore 1.4.6 allows remote attackers to inject arbitrary JavaScript via the PATH_INFO in an acp.php URL, due to use of unsanitized $_SERVER['PHP_SELF'] to generate URLs.
0
Attacker Value
Unknown
CVE-2017-8868
Disclosure Date: May 10, 2017 (last updated November 26, 2024)
acp/core/files.browser.php in flatCore 1.4.7 allows file deletion via directory traversal in the delete parameter to acp/acp.php. The risk might be limited to requests submitted through CSRF.
0