2 results (0.001 seconds)

CVSS: 8.0EPSS: 0%CPEs: 1EXPL: 1

28 Oct 2021 — flatcore-cms is vulnerable to Unrestricted Upload of File with Dangerous Type flatcore-cms es vulnerable a una Carga no Restringida de Archivos de Tipo Peligroso • https://github.com/flatcore/flatcore-cms/commit/5cc3937b6bc38293ec921a5cf00018b48b668dc6 • CWE-434: Unrestricted Upload of File with Dangerous Type •

CVSS: 7.5EPSS: 0%CPEs: 1EXPL: 0

10 May 2017 — acp/core/files.browser.php in flatCore 1.4.7 allows file deletion via directory traversal in the delete parameter to acp/acp.php. The risk might be limited to requests submitted through CSRF. Acp/core/files.browser.php en flatCore 1.4.7 permite la eliminación de archivos a través de directorio traversal en el parámetro delete a acp/acp.php. El riesgo podría estar limitado a las solicitudes enviadas a través de CSRF. • https://github.com/flatCore/flatCore-CMS/issues/30 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •