74cms Vulnerabilities and Affected Products
Vulnerabilities associated with 74cms.
Products
Clear product- 74cms4 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2024-2561MEDIUM | 74CMS Company Logo Index.php#sendCompanyLogo unrestricted uploadA vulnerability, which was classified as critical, has been found in 74CMS 3.28.0. Affected by this issue is the function sendCompanyLogo of the file /controller/company/Index.php#sendCompanyLogo of the component Company Logo Handler. The manipulation of the argument imgBase64 leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-257060. CWE-434Mar 17, 2024 | CVSS6.3v3.1 | EPSS6.08% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-22211CRITICAL | 74cms 74cms Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')SQL Injection in 74cms 3.2.0 via the key parameter to plus/ajax_street.php. | CVSS9.8v3.1 | EPSS7.94% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2020-22208CRITICAL | 74cms 74cms Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')SQL Injection in 74cms 3.2.0 via the x parameter to plus/ajax_street.php. | CVSS9.8v3.1 | EPSS10% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2020-29279CRITICAL | 74cms 74cms Improper Control of Generation of Code ('Code Injection')PHP remote file inclusion in the assign_resume_tpl method in Application/Common/Controller/BaseController.class.php in 74CMS before 6.0.48 allows remote code execution. Dec 2, 20201 related artifact | CVSS9.8v3.1 | EPSS52.9% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |