Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7j4h-3gjv-68v3

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

cms_write.php in Primitive CMS 1.0.9 does not properly restrict access, which allows remote attackers to gain administrative privileges via a direct request. NOTE: this vulnerability can be leveraged to conduct cross-site scripting attacks, as demonstrated using the (1) title, (2) content, and (3) menutitle parameters.

cms_write.php in Primitive CMS 1.0.9 does not properly restrict access, which allows remote attackers to gain administrative privileges via a direct request. NOTE: this vulnerability can be leveraged to conduct cross-site scripting attacks, as demonstrated using the (1) title, (2) content, and (3) menutitle parameters.

EPSS

Процентиль: 83%
0.02006
Низкий

Связанные уязвимости

nvd
больше 15 лет назад

cms_write.php in Primitive CMS 1.0.9 does not properly restrict access, which allows remote attackers to gain administrative privileges via a direct request. NOTE: this vulnerability can be leveraged to conduct cross-site scripting attacks, as demonstrated using the (1) title, (2) content, and (3) menutitle parameters.

EPSS

Процентиль: 83%
0.02006
Низкий