Vulnerabilities (CVE)

Filtered by vendor Metalgenix Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-10057 1 Metalgenix 1 Genixcms 2020-03-05 6.8 MEDIUM 8.8 HIGH
GeniXCMS 1.1.7 is vulnerable to user privilege escalation due to broken access control. This issue exists because of an incomplete fix for CVE-2015-2680, in which "token" is used as a CSRF protection mechanism, but without validation that "token" is associated with an administrative user.
CVE-2017-5520 1 Metalgenix 1 Genixcms 2019-10-03 6.5 MEDIUM 8.8 HIGH
The media rename feature in GeniXCMS through 0.0.8 does not consider alternative PHP file extensions when checking uploaded files for PHP content, which enables a user to rename and execute files with the `.php6`, `.php7` and `.phtml` extensions.
CVE-2017-6065 1 Metalgenix 1 Genixcms 2017-02-23 6.5 MEDIUM 8.8 HIGH
SQL injection vulnerability in inc/lib/Control/Backend/menus.control.php in GeniXCMS through 1.0.2 allows remote authenticated users to execute arbitrary SQL commands via the order parameter.
CVE-2017-5518 1 Metalgenix 1 Genixcms 2017-01-27 4.3 MEDIUM 7.4 HIGH
The media-file upload feature in GeniXCMS through 0.0.8 allows remote attackers to conduct SSRF attacks via a URL, as demonstrated by a URL with an intranet IP address.
CVE-2017-5347 1 Metalgenix 1 Genixcms 2017-01-27 6.5 MEDIUM 7.2 HIGH
SQL injection vulnerability in inc/mod/newsletter/options.php in GeniXCMS 0.0.8 allows remote authenticated administrators to execute arbitrary SQL commands via the recipient parameter to gxadmin/index.php.
CVE-2017-5345 1 Metalgenix 1 Genixcms 2017-01-27 6.5 MEDIUM 8.8 HIGH
SQL injection vulnerability in inc/lib/Control/Ajax/tags-ajax.control.php in GeniXCMS 0.0.8 allows remote authenticated editors to execute arbitrary SQL commands via the term parameter to the default URI.