Show filters
14 Total Results
Displaying 1-10 of 14
Sort by:
Attacker Value
Unknown
CVE-2023-51252
Disclosure Date: January 10, 2024 (last updated January 17, 2024)
PublicCMS 4.0 is vulnerable to Cross Site Scripting (XSS). Because files can be uploaded and online preview function is provided, pdf files and html files containing malicious code are uploaded, an XSS popup window is realized through online viewing.
0
Attacker Value
Unknown
CVE-2023-46990
Disclosure Date: November 20, 2023 (last updated November 29, 2023)
Deserialization of Untrusted Data in PublicCMS v.4.0.202302.e allows a remote attacker to execute arbitrary code via a crafted script to the writeReplace function.
0
Attacker Value
Unknown
CVE-2023-48204
Disclosure Date: November 16, 2023 (last updated November 21, 2023)
An issue in PublicCMS v.4.0.202302.e allows a remote attacker to obtain sensitive information via the appToken and Parameters parameter of the api/method/getHtml component.
0
Attacker Value
Unknown
CVE-2020-20915
Disclosure Date: April 04, 2023 (last updated February 24, 2025)
SQL Injection vulnerability found in PublicCMS v.4.0 allows a remote attacker to execute arbitrary code via sql parameter of the the SysSiteAdminControl.
0
Attacker Value
Unknown
CVE-2020-20914
Disclosure Date: April 04, 2023 (last updated February 24, 2025)
SQL Injection vulnerability found in San Luan PublicCMS v.4.0 allows a remote attacker to execute arbitrary code via the sql parameter.
0
Attacker Value
Unknown
CVE-2022-23389
Disclosure Date: February 14, 2022 (last updated February 23, 2025)
PublicCMS v4.0 was discovered to contain a remote code execution (RCE) vulnerability via the cmdarray parameter.
0
Attacker Value
Unknown
CVE-2021-40881
Disclosure Date: September 15, 2021 (last updated February 23, 2025)
An issue in the BAT file parameters of PublicCMS v4.0 allows attackers to execute arbitrary code.
0
Attacker Value
Unknown
CVE-2020-21333
Disclosure Date: July 09, 2021 (last updated February 23, 2025)
Cross Site Scripting (XSS) vulnerability in PublicCMS 4.0 to get an admin cookie when the Administrator reviews submit case.
0
Attacker Value
Unknown
CVE-2018-18927
Disclosure Date: November 04, 2018 (last updated November 27, 2024)
An issue was discovered in PublicCMS V4.0. It allows XSS by modifying the page_list "attached" attribute (which typically has 'class="icon-globe icon-large"' in its value), as demonstrated by an 'UPDATE sys_module SET attached = "[XSS]" WHERE id="page_list"' statement.
0
Attacker Value
Unknown
CVE-2018-17368
Disclosure Date: September 23, 2018 (last updated November 27, 2024)
An issue was discovered in PublicCMS V4.0.180825. For an invalid login attempt, the response length is different depending on whether the username is valid, which makes it easier to conduct brute-force attacks.
0