Show filters
5 Total Results
Displaying 1-5 of 5
Sort by:
Attacker Value
Unknown

CVE-2022-3464

Disclosure Date: October 12, 2022 (last updated February 24, 2025)
A vulnerability classified as problematic has been found in puppyCMS up to 5.1. This affects an unknown part of the file /admin/settings.php. The manipulation of the argument site_name leads to cross site scripting. It is possible to initiate the attack remotely. The associated identifier of this vulnerability is VDB-210699.
Attacker Value
Unknown

CVE-2020-18890

Disclosure Date: May 06, 2021 (last updated February 22, 2025)
Rmote Code Execution (RCE) vulnerability in puppyCMS v5.1 due to insecure permissions, which could let a remote malicious user getshell via /admin/functions.php.
Attacker Value
Unknown

CVE-2020-18888

Disclosure Date: May 06, 2021 (last updated February 22, 2025)
Arbitrary File Deletion vulnerability in puppyCMS v5.1 allows remote malicious attackers to delete the file/folder via /admin/functions.php.
Attacker Value
Unknown

CVE-2020-18889

Disclosure Date: May 06, 2021 (last updated February 22, 2025)
Cross Site Request Forgery (CSRF) vulnerability in puppyCMS v5.1 that can change the admin's password via /admin/settings.php.
Attacker Value
Unknown

CVE-2018-15847

Disclosure Date: August 25, 2018 (last updated November 27, 2024)
An issue was discovered in puppyCMS 5.1. There is an XSS vulnerability via menu.php in the "Add Page/URL" URL link field.
0