Show filters
14 Total Results
Displaying 1-10 of 14
Sort by:
Attacker Value
Unknown

CVE-2023-51252

Disclosure Date: January 10, 2024 (last updated January 17, 2024)
PublicCMS 4.0 is vulnerable to Cross Site Scripting (XSS). Because files can be uploaded and online preview function is provided, pdf files and html files containing malicious code are uploaded, an XSS popup window is realized through online viewing.
Attacker Value
Unknown

CVE-2023-46990

Disclosure Date: November 20, 2023 (last updated November 29, 2023)
Deserialization of Untrusted Data in PublicCMS v.4.0.202302.e allows a remote attacker to execute arbitrary code via a crafted script to the writeReplace function.
Attacker Value
Unknown

CVE-2023-48204

Disclosure Date: November 16, 2023 (last updated November 21, 2023)
An issue in PublicCMS v.4.0.202302.e allows a remote attacker to obtain sensitive information via the appToken and Parameters parameter of the api/method/getHtml component.
Attacker Value
Unknown

CVE-2020-20915

Disclosure Date: April 04, 2023 (last updated February 24, 2025)
SQL Injection vulnerability found in PublicCMS v.4.0 allows a remote attacker to execute arbitrary code via sql parameter of the the SysSiteAdminControl.
Attacker Value
Unknown

CVE-2020-20914

Disclosure Date: April 04, 2023 (last updated February 24, 2025)
SQL Injection vulnerability found in San Luan PublicCMS v.4.0 allows a remote attacker to execute arbitrary code via the sql parameter.
Attacker Value
Unknown

CVE-2022-23389

Disclosure Date: February 14, 2022 (last updated February 23, 2025)
PublicCMS v4.0 was discovered to contain a remote code execution (RCE) vulnerability via the cmdarray parameter.
Attacker Value
Unknown

CVE-2021-40881

Disclosure Date: September 15, 2021 (last updated February 23, 2025)
An issue in the BAT file parameters of PublicCMS v4.0 allows attackers to execute arbitrary code.
Attacker Value
Unknown

CVE-2020-21333

Disclosure Date: July 09, 2021 (last updated February 23, 2025)
Cross Site Scripting (XSS) vulnerability in PublicCMS 4.0 to get an admin cookie when the Administrator reviews submit case.
Attacker Value
Unknown

CVE-2018-18927

Disclosure Date: November 04, 2018 (last updated November 27, 2024)
An issue was discovered in PublicCMS V4.0. It allows XSS by modifying the page_list "attached" attribute (which typically has 'class="icon-globe icon-large"' in its value), as demonstrated by an 'UPDATE sys_module SET attached = "[XSS]" WHERE id="page_list"' statement.
0
Attacker Value
Unknown

CVE-2018-17368

Disclosure Date: September 23, 2018 (last updated November 27, 2024)
An issue was discovered in PublicCMS V4.0.180825. For an invalid login attempt, the response length is different depending on whether the username is valid, which makes it easier to conduct brute-force attacks.
0