Show filters
2 Total Results
Displaying 1-2 of 2
Sort by:
Attacker Value
Unknown

CVE-2022-24652

Disclosure Date: March 10, 2022 (last updated February 23, 2025)
sentcms 4.0.x allows remote attackers to cause arbitrary file uploads through an unauthorized file upload interface, resulting in php code execution in /admin/upload/upload.
Attacker Value
Unknown

CVE-2022-24651

Disclosure Date: March 10, 2022 (last updated February 23, 2025)
sentcms 4.0.x allows remote attackers to cause arbitrary file uploads through an unauthorized file upload interface, resulting in PHP code execution through /user/upload/upload.