Filtered by vendor Brassica
Subscribe
Search
Total
2 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2020-15189 | 1 Brassica | 1 Soy Cms | 2020-09-29 | 6.5 MEDIUM | 7.2 HIGH |
| SOY CMS 3.0.2 and earlier is affected by Remote Code Execution (RCE) using Unrestricted File Upload. Cross-Site Scripting(XSS) vulnerability that was used in CVE-2020-15183 can be used to increase impact by redirecting the administrator to access a specially crafted page. This vulnerability is caused by insecure configuration in elFinder. This is fixed in version 3.0.2.328. | |||||
| CVE-2019-11376 | 1 Brassica | 1 Soy Cms | 2019-04-22 | 6.5 MEDIUM | 7.2 HIGH |
| ** DISPUTED ** SOY CMS v3.0.2 allows remote attackers to execute arbitrary PHP code via a <?php substring in the second text box. NOTE: the vendor indicates that there was an assumption that the content is "made editable on its own." | |||||
