Showing 2 vulnerabilities on this page for asgaros_forum

Signals CISA KEV Ransomware Nuclei
asgaros vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Asgaros Forum < 2.7.1 - Unauthenticated Arbitrary File Upload

The Asgaros Forum WordPress plugin before 2.7.1 allows forum administrators, who may not be WordPress (super-)administrators, to set insecure configuration that allows unauthenticated users to upload dangerous files (e.g. .php, .phtml), potentially leading to remote code execution.

CWE-434CWE-94Nov 27, 2023
CVSS9.8v3.1EPSS1.96%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Asgaros Forum < 1.15.13 - Unauthenticated SQL Injection

The Asgaros Forum WordPress plugin before 1.15.13 does not validate and escape user input when subscribing to a topic before using it in a SQL statement, leading to an unauthenticated SQL injection issue

CWE-89Nov 8, 20211 related artifact
CVSS9.8v3.1EPSS13.3%PoCs0SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX