Showing 4 vulnerabilities on this page for 74cms

Signals CISA KEV Ransomware Nuclei
74cms vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

74CMS Company Logo Index.php#sendCompanyLogo unrestricted upload

A vulnerability, which was classified as critical, has been found in 74CMS 3.28.0. Affected by this issue is the function sendCompanyLogo of the file /controller/company/Index.php#sendCompanyLogo of the component Company Logo Handler. The manipulation of the argument imgBase64 leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-257060.

CWE-434Mar 17, 2024
CVSS6.3v3.1EPSS6.08%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

74cms 74cms Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

SQL Injection in 74cms 3.2.0 via the key parameter to plus/ajax_street.php.

CWE-89Jun 16, 20211 related artifact
CVSS9.8v3.1EPSS7.94%PoCs0SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

74cms 74cms Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

SQL Injection in 74cms 3.2.0 via the x parameter to plus/ajax_street.php.

CWE-89Jun 16, 20211 related artifact
CVSS9.8v3.1EPSS10%PoCs0SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

74cms 74cms Improper Control of Generation of Code ('Code Injection')

PHP remote file inclusion in the assign_resume_tpl method in Application/Common/Controller/BaseController.class.php in 74CMS before 6.0.48 allows remote code execution.

Dec 2, 20201 related artifact
CVSS9.8v3.1EPSS52.9%PoCs0SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX