Vulnerabilities (CVE)

Filtered by vendor Typesettercms Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-25790 1 Typesettercms 1 Typesetter 2020-10-20 6.5 MEDIUM 7.2 HIGH
** DISPUTED ** Typesetter CMS 5.x through 5.1 allows admins to upload and execute arbitrary PHP code via a .php file inside a ZIP archive. NOTE: the vendor disputes the significance of this report because "admins are considered trustworthy"; however, the behavior "contradicts our security policy" and is being fixed for 5.2.
CVE-2018-6888 1 Typesettercms 1 Typesetter 2018-03-06 6.0 MEDIUM 8.0 HIGH
An issue was discovered in Typesetter 5.1. The User Permissions page (aka Admin/Users) suffers from critical flaw of Cross Site Request forgery: using a forged HTTP request, a malicious user can lead a user to unknowingly create / delete or modify a user account due to the lack of an anti-CSRF token.
CVE-2018-6889 1 Typesettercms 1 Typesetter 2018-03-06 6.5 MEDIUM 8.8 HIGH
An issue was discovered in Typesetter 5.1. It suffers from a Host header injection vulnerability, Using this attack, a malicious user can poison the web cache or perform advanced password reset attacks or even trigger arbitrary user re-direction.