Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Lovejackey

#20897of 53,624
12Total CVSS
Vulnerabilities · 2
Medium
2
PT-2018-14944
6.5
2018-11-20
Greencms · Greencms · CVE-2018-19376
**Name of the Vulnerable Software and Affected Versions** GreenCMS version 2.3.0603 **Description** An issue was discovered that allows attackers to delete a log file due to a CSRF vulnerability. This can be achieved via the "index.php?m=admin&c=data&a=clear" URI. **Recommendations** For GreenCMS version 2.3.0603, as a temporary workaround, consider restricting access to the "index.php?m=admin&c=data&a=clear" URI to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.
PT-2018-14919
5.5
2018-11-17
Greencms · Greencms · CVE-2018-19329
**Name of the Vulnerable Software and Affected Versions** GreenCMS version 2.3.0603 **Description** The issue allows remote authenticated administrators to delete arbitrary files by modifying a base64-encoded pathname in an "m=admin&c=media&a=delfilehandle&id=" call. This is related to the delete button in the "m=admin&c=media&a=restorefile" functionality. **Recommendations** For GreenCMS version 2.3.0603, consider restricting access to the "m=admin&c=media&a=delfilehandle&id=" endpoint to prevent arbitrary file deletion until a fix is available. As a temporary workaround, limit the use of the delete button in the "m=admin&c=media&a=restorefile" functionality to minimize the risk of exploitation.