CVE-2024-8335 – OpenRapid RapidCMS runlogon.php sql injection
https://notcve.org/view.php?id=CVE-2024-8335
30 Aug 2024 — A vulnerability classified as critical has been found in OpenRapid RapidCMS up to 1.3.1. Affected is an unknown function of the file /resource/runlogon.php. The manipulation of the argument username leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. • https://vuldb.com/?id.276210 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •
CVE-2024-8331 – OpenRapid RapidCMS user-move-run.php sql injection
https://notcve.org/view.php?id=CVE-2024-8331
30 Aug 2024 — A vulnerability was found in OpenRapid RapidCMS up to 1.3.1. It has been classified as critical. This affects an unknown part of the file /admin/user/user-move-run.php. The manipulation of the argument username leads to sql injection. It is possible to initiate the attack remotely. • https://gitee.com/A0kooo/cve_article/blob/master/RapidCMS/SQL%20injection1/rapidcms%20user-move-run.php%20SQL%20injection.md • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •
CVE-2023-5262 – OpenRapid RapidCMS uploadicon.php isImg unrestricted upload
https://notcve.org/view.php?id=CVE-2023-5262
29 Sep 2023 — A vulnerability has been found in OpenRapid RapidCMS 1.3.1 and classified as critical. Affected by this vulnerability is the function isImg of the file /admin/config/uploadicon.php. The manipulation of the argument fileName leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. • https://github.com/OpenRapid/rapidcms/issues/10 • CWE-434: Unrestricted Upload of File with Dangerous Type •
CVE-2023-5258 – OpenRapid RapidCMS addgood.php sql injection
https://notcve.org/view.php?id=CVE-2023-5258
29 Sep 2023 — A vulnerability classified as critical has been found in OpenRapid RapidCMS 1.3.1. This affects an unknown part of the file /resource/addgood.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. • https://github.com/OpenRapid/rapidcms/issues/9 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •
CVE-2023-5033 – OpenRapid RapidCMS cate-edit-run.php sql injection
https://notcve.org/view.php?id=CVE-2023-5033
18 Sep 2023 — A vulnerability classified as critical has been found in OpenRapid RapidCMS 1.3.1. This affects an unknown part of the file /admin/category/cate-edit-run.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. • https://github.com/yhy217/rapidcms-vul/issues/3 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •
CVE-2023-5032 – OpenRapid RapidCMS article-edit-run.php sql injection
https://notcve.org/view.php?id=CVE-2023-5032
18 Sep 2023 — A vulnerability was found in OpenRapid RapidCMS 1.3.1. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/article/article-edit-run.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. • https://github.com/yhy217/rapidcms-vul/issues/2 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •
CVE-2023-5031 – OpenRapid RapidCMS article-add.php sql injection
https://notcve.org/view.php?id=CVE-2023-5031
18 Sep 2023 — A vulnerability was found in OpenRapid RapidCMS 1.3.1. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/article/article-add.php. The manipulation of the argument id leads to sql injection. The attack can be launched remotely. • https://github.com/yhy217/rapidcms-vul/issues/1 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •
CVE-2023-4448 – OpenRapid RapidCMS run-movepass.php password recovery
https://notcve.org/view.php?id=CVE-2023-4448
21 Aug 2023 — A vulnerability was found in OpenRapid RapidCMS 1.3.1 and classified as critical. This issue affects some unknown processing of the file admin/run-movepass.php. The manipulation of the argument password/password2 leads to weak password recovery. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. • https://github.com/OpenRapid/rapidcms/commit/4dff387283060961c362d50105ff8da8ea40bcbe#diff-fc57d4c69cf5912c6edb5233c6df069a91106ebd481c115faf1ea124478b26d0 • CWE-640: Weak Password Recovery Mechanism for Forgotten Password •
CVE-2023-4447 – OpenRapid RapidCMS article-chat.php sql injection
https://notcve.org/view.php?id=CVE-2023-4447
21 Aug 2023 — A vulnerability has been found in OpenRapid RapidCMS 1.3.1 and classified as critical. This vulnerability affects unknown code of the file admin/article-chat.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. • https://github.com/OpenRapid/rapidcms/issues/4 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •
CVE-2023-4446 – OpenRapid RapidCMS category.php sql injection
https://notcve.org/view.php?id=CVE-2023-4446
21 Aug 2023 — A vulnerability, which was classified as critical, was found in OpenRapid RapidCMS 1.3.1. This affects an unknown part of the file template/default/category.php. The manipulation of the argument id leads to sql injection. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-237567. • https://github.com/OpenRapid/rapidcms/issues/3 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •