Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Aoaoaoe

#41548of 53,635
6.5Total CVSS
Vulnerabilities · 1
PT-2023-30729
6.5
2023-11-15
Publiccms · Publiccms · CVE-2023-48204
**Name of the Vulnerable Software and Affected Versions** PublicCMS version 4.0.202302.e **Description** The issue allows a remote attacker to obtain sensitive information via the `appToken` and `Parameters` parameter of the "api/method/getHtml" component. **Recommendations** For PublicCMS version 4.0.202302.e, as a temporary workaround, consider restricting access to the "api/method/getHtml" component until a patch is available. Avoid using the `appToken` and `Parameters` parameters in this component to minimize the risk of exploitation.