Vulnerabilities (CVE)

Filtered by vendor Squiz Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2019-19373 1 Squiz 1 Matrix 2019-12-19 5.0 MEDIUM 7.5 HIGH
An issue was discovered in Squiz Matrix CMS 5.5.0 prior to 5.5.0.3, 5.5.1 prior to 5.5.1.8, 5.5.2 prior to 5.5.2.4, and 5.5.3 prior to 5.5.3.3 where a user can trigger arbitrary unserialization of a PHP object from a packages/cms/page_templates/page_remote_content/page_remote_content.inc POST parameter during processing of a Remote Content page type. This unserialization can be used to trigger the inclusion of arbitrary files on the filesystem (local file inclusion), and results in remote code execution.
CVE-2017-14198 1 Squiz 1 Matrix 2019-10-03 6.5 MEDIUM 8.8 HIGH
An issue was discovered in Squiz Matrix before 5.3.6.1 and 5.4.x before 5.4.1.3. Authenticated users with permissions to edit design assets can cause Remote Code Execution (RCE) via a maliciously crafted time_format tag.
CVE-2017-14196 1 Squiz 1 Matrix 2017-12-14 5.0 MEDIUM 7.5 HIGH
An issue was discovered in Squiz Matrix from 5.3 through to 5.3.6.1 and 5.4.1.3. An information disclosure caused by a Path Traversal issue in the 'File Bridge' plugin allowed the existence of files outside of the bridged path to be confirmed.