CVE-2023-4448 – OpenRapid RapidCMS run-movepass.php password recovery
https://notcve.org/view.php?id=CVE-2023-4448
21 Aug 2023 — A vulnerability was found in OpenRapid RapidCMS 1.3.1 and classified as critical. This issue affects some unknown processing of the file admin/run-movepass.php. The manipulation of the argument password/password2 leads to weak password recovery. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. • https://github.com/OpenRapid/rapidcms/commit/4dff387283060961c362d50105ff8da8ea40bcbe#diff-fc57d4c69cf5912c6edb5233c6df069a91106ebd481c115faf1ea124478b26d0 • CWE-640: Weak Password Recovery Mechanism for Forgotten Password •
CVE-2023-4447 – OpenRapid RapidCMS article-chat.php sql injection
https://notcve.org/view.php?id=CVE-2023-4447
21 Aug 2023 — A vulnerability has been found in OpenRapid RapidCMS 1.3.1 and classified as critical. This vulnerability affects unknown code of the file admin/article-chat.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. • https://github.com/OpenRapid/rapidcms/issues/4 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •
CVE-2023-4446 – OpenRapid RapidCMS category.php sql injection
https://notcve.org/view.php?id=CVE-2023-4446
21 Aug 2023 — A vulnerability, which was classified as critical, was found in OpenRapid RapidCMS 1.3.1. This affects an unknown part of the file template/default/category.php. The manipulation of the argument id leads to sql injection. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-237567. • https://github.com/OpenRapid/rapidcms/issues/3 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •