Vulnerabilities (CVE)

Filtered by vendor Baijiacms Project Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-45942 1 Baijiacms Project 1 Baijiacms 2023-08-08 N/A 8.8 HIGH
A Remote Code Execution (RCE) vulnerability was found in includes/baijiacms/common.inc.php in baijiacms v4.
CVE-2018-10503 1 Baijiacms Project 1 Baijiacms 2019-12-03 6.8 MEDIUM 8.8 HIGH
An issue was discovered in index.php in baijiacms V4 v4_1_4_20170105. CSRF allows adding an administrator account via op=edituser, changing the administrator password via op=changepwd, or deleting an account via op=deleteuser.
CVE-2018-10249 1 Baijiacms Project 1 Baijiacms 2018-05-22 6.8 MEDIUM 8.8 HIGH
baijiacms V3 has CSRF via index.php?mod=site&op=edituser&name=manager&do=user to add an administrator account.