Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Xichao

#15260of 53,630
17.6Total CVSS
Vulnerabilities · 2
High
2
PT-2018-10740
8.8
2018-06-01
Greencms · Greencms · CVE-2018-11670
**Name of the Vulnerable Software and Affected Versions** GreenCMS version 2.3.0603 **Description** A CSRF issue allows attackers to execute arbitrary PHP code via the `content` parameter to "index.php?m=admin&c=media&a=fileconnect" API endpoint. **Recommendations** For GreenCMS version 2.3.0603, as a temporary workaround, consider restricting access to the "index.php?m=admin&c=media&a=fileconnect" API endpoint until a patch is available. Avoid using the `content` parameter in this endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this issue.
PT-2018-10741
8.8
2018-06-01
Greencms · Greencms · CVE-2018-11671
**Name of the Vulnerable Software and Affected Versions** GreenCMS version 2.3.0603 **Description** An issue was discovered that allows for a CSRF vulnerability, enabling the addition of an admin account via the "index.php?m=admin&c=access&a=adduserhandle" endpoint. **Recommendations** For GreenCMS version 2.3.0603, as a temporary workaround, consider restricting access to the `adduserhandle` action in the `access` controller to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.