Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Gift89Ao

#20798of 53,630
12.1Total CVSS
Vulnerabilities · 2
Medium
1
High
1
PT-2023-12080
4.9
2023-08-11
Supermicro · Pcmt Supermicro-Cms · CVE-2021-25856
**Name of the Vulnerable Software and Affected Versions** pcmt superMicro-CMS version 3.11 **Description** An issue was discovered that allows attackers to delete files via a crafted image file in the `images.php` file. **Recommendations** For pcmt superMicro-CMS version 3.11, consider restricting access to the `images.php` file until a patch is available. As a temporary workaround, avoid using the `images.php` file to minimize the risk of exploitation.
PT-2023-12081
7.2
2023-08-11
Supermicro · Pcmt Supermicro-Cms · CVE-2021-25857
**Name of the Vulnerable Software and Affected Versions** pcmt superMicro-CMS version 3.11 **Description** An issue in pcmt superMicro-CMS allows authenticated attackers to execute arbitrary code via the `font type` parameter to "setup.php". **Recommendations** For pcmt superMicro-CMS version 3.11, avoid using the `font type` parameter in the "setup.php" endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.