Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Oyeahtime

#16791of 53,619
16Total CVSS
Vulnerabilities · 2
High
2
PT-2018-11088
8.8
2018-06-13
Portfoliocms · Portfoliocms · CVE-2018-12263
**Name of the Vulnerable Software and Affected Versions** portfolioCMS version 1.0.5 **Description** The issue allows the upload of arbitrary .php files via the "admin/portfolio.php?newpage=true" API endpoint. This could potentially lead to unauthorized code execution. **Recommendations** For portfolioCMS version 1.0.5, consider restricting access to the "admin/portfolio.php?newpage=true" API endpoint until a patch is available. As a temporary workaround, disabling the file upload functionality in the admin interface may help minimize the risk of exploitation.
PT-2018-11020
7.2
2018-06-11
Portfoliocms · Portfoliocms · CVE-2018-12110
**Name of the Vulnerable Software and Affected Versions** portfolioCMS version 1.0.5 **Description** The issue is related to SQL Injection, which can be exploited via the `preview` parameter in the "admin/portfolio.php" endpoint. **Recommendations** For portfolioCMS version 1.0.5, avoid using the `preview` parameter in the "admin/portfolio.php" endpoint until the issue is resolved.