Show filters
4 Total Results
Displaying 1-4 of 4
Sort by:
Attacker Value
Unknown

CVE-2022-38796

Disclosure Date: September 14, 2022 (last updated February 24, 2025)
A Host Header Injection vulnerability in Feehi CMS 2.1.1 may allow an attacker to spoof a particular header. This can be exploited by abusing password reset emails.
Attacker Value
Unknown

CVE-2022-34140

Disclosure Date: July 28, 2022 (last updated February 24, 2025)
A stored cross-site scripting (XSS) vulnerability in /index.php?r=site%2Fsignup of Feehi CMS v2.1.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the username field.
Attacker Value
Unknown

CVE-2022-34971

Disclosure Date: July 27, 2022 (last updated February 24, 2025)
An arbitrary file upload vulnerability in the Advertising Management module of Feehi CMS v2.1.1 allows attackers to execute arbitrary code via a crafted PHP file.
Attacker Value
Unknown

CVE-2021-30108

Disclosure Date: May 24, 2021 (last updated February 22, 2025)
Feehi CMS 2.1.1 is affected by a Server-side request forgery (SSRF) vulnerability. When the user modifies the HTTP Referer header to any url, the server can make a request to it.