Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-q6c8-7rvq-2f39

Опубликовано: 02 мая 2022
Источник: github
Github: Не прошло ревью

Описание

LoveCMS 1.6.2 does not require administrative authentication for (1) addblock.php, (2) blocks.php, and (3) themes.php in system/admin/, which allows remote attackers to change the configuration or execute arbitrary PHP code via addition of blocks, and other vectors.

LoveCMS 1.6.2 does not require administrative authentication for (1) addblock.php, (2) blocks.php, and (3) themes.php in system/admin/, which allows remote attackers to change the configuration or execute arbitrary PHP code via addition of blocks, and other vectors.

EPSS

Процентиль: 94%
0.15097
Средний

Дефекты

CWE-94

Связанные уязвимости

nvd
больше 17 лет назад

LoveCMS 1.6.2 does not require administrative authentication for (1) addblock.php, (2) blocks.php, and (3) themes.php in system/admin/, which allows remote attackers to change the configuration or execute arbitrary PHP code via addition of blocks, and other vectors.

EPSS

Процентиль: 94%
0.15097
Средний

Дефекты

CWE-94