Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Hanayuzu

#13587of 53,633
19.6Total CVSS
Vulnerabilities · 2
Critical
2
PT-2022-16774
9.8
2022-03-10
Sentcms · Sentcms · CVE-2022-24651
**Name of the Vulnerable Software and Affected Versions** sentcms versions 4.0.x **Description** The issue allows remote attackers to cause arbitrary file uploads through an unauthorized file upload interface, resulting in PHP code execution through the "/user/upload/upload" API endpoint. **Recommendations** For sentcms versions 4.0.x, consider disabling the file upload feature or restricting access to the "/user/upload/upload" API endpoint until a patch is available.
PT-2022-16775
9.8
2022-03-10
Sentcms · Sentcms · CVE-2022-24652
**Name of the Vulnerable Software and Affected Versions** sentcms versions 4.0.x **Description** The issue allows remote attackers to cause arbitrary file uploads through an unauthorized file upload interface, resulting in PHP code execution in the /admin/upload/upload endpoint. **Recommendations** For sentcms versions 4.0.x, consider disabling the file upload functionality in the /admin/upload/upload endpoint until a patch is available to prevent arbitrary file uploads and potential PHP code execution.