mozilo Vulnerabilities and Affected Products
Vulnerabilities associated with mozilocms.
Products
Clear product- mozilocms2 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2024-44871HIGH | MoziloCMS 3.0 - Remote Code Execution (RCE)An arbitrary file upload vulnerability in the component /admin/index.php of moziloCMS v3.0 allows attackers to execute arbitrary code via uploading a crafted file. CWE-434Sep 10, 2024 | CVSS7.2v3.1 | EPSS16.2% | PoCs2 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-29368MEDIUM | An arbitrary file upload vulnerability in the file handling module of moziloCMS v2.0 allows attackers to bypass extension restrictions via file renaming, potentially leading to unauthorized file execution or storage of malicious content. CWE-434Apr 22, 2024 | CVSS6.5v3.1 | EPSS0.759% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |