Show filters
4 Total Results
Displaying 1-4 of 4
Sort by:
Attacker Value
Unknown

CVE-2017-1000428

Disclosure Date: January 10, 2018 (last updated November 26, 2024)
flatCore-CMS 1.4.6 is vulnerable to reflected XSS in user_management.php due to the use of $_SERVER['PHP_SELF'] to build links and a stored XSS in the admin log panel by specifying a malformed User-Agent string.
0
Attacker Value
Unknown

CVE-2017-7878

Disclosure Date: April 14, 2017 (last updated November 26, 2024)
SQL Injection vulnerability in flatCore version 1.4.6 allows an attacker to read and write to the users database.
0
Attacker Value
Unknown

CVE-2017-7877

Disclosure Date: April 14, 2017 (last updated November 26, 2024)
CSRF vulnerability in flatCore version 1.4.6 allows remote attackers to modify CMS configurations.
0
Attacker Value
Unknown

CVE-2017-7879

Disclosure Date: April 14, 2017 (last updated November 26, 2024)
SQL Injection vulnerability in flatCore version 1.4.6 allows an attacker to read the content database.
0