Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

M0Us3Sun

#35536of 53,630
7.5Total CVSS
Vulnerabilities · 1
PT-2018-12816
7.5
2018-08-05
Phpcms · Phpcms · CVE-2018-14940
**Name of the Vulnerable Software and Affected Versions** PHPCMS version 9 **Description** The issue allows remote attackers to cause a denial of service, specifically resource consumption, by sending a request to the "api.php?op=checkcode" endpoint with large values for the `font size`, `height`, and `width` parameters. **Recommendations** For PHPCMS version 9, consider restricting access to the "api.php?op=checkcode" endpoint or limiting the values that can be passed for the `font size`, `height`, and `width` parameters to prevent denial of service attacks.