Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Passtion

#21856of 53,625
10.8Total CVSS
Vulnerabilities · 2
Medium
2
PT-2017-11644
4.3
2017-07-06
Finecms · Finecms · CVE-2017-10967
**Name of the Vulnerable Software and Affected Versions** FineCMS versions prior to 2017-07-06 **Description** The issue allows for XSS in the `key name`, `key value`, and `meaning` parameters within the application/core/controller/config.php file. **Recommendations** For versions prior to 2017-07-06, update to a version released after 2017-07-06 to resolve the issue.
PT-2017-11650
6.5
2017-07-06
Finecms · Finecms · CVE-2017-10973
**Name of the Vulnerable Software and Affected Versions** FineCMS versions prior to 2017-07-06 **Description** The issue is related to Server-Side Request Forgery (SSRF) in the application/lib/ajax/get image data.php file. It occurs when requests are made for non-image files with a modified HTTP Host header. **Recommendations** For versions prior to 2017-07-06, update to a version released after 2017-07-06 to resolve the issue.