Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Sunu11

#16779de 53,633
16CVSS total
Vulnerabilidades · 2
Alta
2
PT-2018-14736
7.2
2018-11-05
Baser · Basercms · CVE-2018-18942
**Name of the Vulnerable Software and Affected Versions** baserCMS versions prior to 4.1.4 **Description** The issue allows remote attackers to execute arbitrary PHP code. This is achieved via the `admin/theme configs/form` data, specifically through the `ThemeConfig][logo` parameter in the `libBaserModelThemeConfig.php` file. **Recommendations** For versions prior to 4.1.4, update to version 4.1.4 or later to resolve the issue. As a temporary workaround, consider restricting access to the `libBaserModelThemeConfig.php` file or disabling the `logo` parameter in the `admin/theme configs/form` data until a patch is applied.
PT-2018-18799
8.8
2018-04-10
Monstra · Monstra Cms · CVE-2018-9037
**Name of the Vulnerable Software and Affected Versions** Monstra CMS version 3.0.4 **Description** The issue allows remote code execution via an upload file request for a .zip file. This .zip file is automatically extracted and may contain .php files, leading to potential code execution. **Recommendations** For Monstra CMS version 3.0.4, consider disabling the upload functionality for .zip files or restricting the types of files that can be uploaded to prevent remote code execution until a patch is available.