Vulnerabilities (CVE)

Filtered by vendor Codelyfe Subscribe
Filtered by product Stupid Simple Cms
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-7040 1 Codelyfe 1 Stupid Simple Cms 2023-12-30 N/A 6.5 MEDIUM
A vulnerability classified as problematic was found in codelyfe Stupid Simple CMS up to 1.2.4. Affected by this vulnerability is an unknown functionality of the file /file-manager/rename.php. The manipulation of the argument oldName leads to path traversal: '../filedir'. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-248689 was assigned to this vulnerability.
CVE-2023-7041 1 Codelyfe 1 Stupid Simple Cms 2023-12-29 N/A 5.4 MEDIUM
A vulnerability, which was classified as critical, has been found in codelyfe Stupid Simple CMS up to 1.2.4. Affected by this issue is some unknown functionality of the file /file-manager/rename.php. The manipulation of the argument newName leads to path traversal: '../filedir'. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-248690 is the identifier assigned to this vulnerability.