Filtered by vendor Bloofox
Subscribe
Search
Total
6 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2020-35759 | 1 Bloofox | 1 Bloofoxcms | 2021-06-17 | 4.3 MEDIUM | 6.5 MEDIUM |
| bloofoxCMS 0.5.2.1 is infected with a CSRF Attack that leads to an attacker editing any file content (Locally/Remotely). | |||||
| CVE-2020-35761 | 1 Bloofox | 1 Bloofoxcms | 2021-06-17 | 3.5 LOW | 5.4 MEDIUM |
| bloofoxCMS 0.5.2.1 is infected with XSS that allows remote attackers to execute arbitrary JS/HTML Code. | |||||
| CVE-2020-36142 | 1 Bloofox | 1 Bloofoxcms | 2021-06-09 | 4.0 MEDIUM | 6.5 MEDIUM |
| BloofoxCMS 0.5.2.1 allows Directory traversal vulnerability by inserting '../' payloads within the 'fileurl' parameter. | |||||
| CVE-2020-35709 | 1 Bloofox | 1 Bloofoxcms | 2021-06-09 | 4.0 MEDIUM | 4.9 MEDIUM |
| bloofoxCMS 0.5.2.1 allows admins to upload arbitrary .php files (with "Content-Type: application/octet-stream") to ../media/images/ via the admin/index.php?mode=tools&page=upload URI, aka directory traversal. | |||||
| CVE-2020-36140 | 1 Bloofox | 1 Bloofoxcms | 2021-06-09 | 4.3 MEDIUM | 6.5 MEDIUM |
| BloofoxCMS 0.5.2.1 allows Cross-Site Request Forgery (CSRF) via 'mode=settings&page=editor', as demonstrated by use of 'mode=settings&page=editor' to change any file content (Locally/Remotely). | |||||
| CVE-2020-36139 | 1 Bloofox | 1 Bloofoxcms | 2021-06-08 | 3.5 LOW | 5.4 MEDIUM |
| BloofoxCMS 0.5.2.1 allows Reflected Cross-Site Scripting (XSS) vulnerability by inserting a XSS payload within the 'fileurl' parameter. | |||||
