
CVE-2021-3745 – Unrestricted Upload of File with Dangerous Type in flatcore/flatcore-cms
https://notcve.org/view.php?id=CVE-2021-3745
28 Oct 2021 — flatcore-cms is vulnerable to Unrestricted Upload of File with Dangerous Type flatcore-cms es vulnerable a una Carga no Restringida de Archivos de Tipo Peligroso • https://github.com/flatcore/flatcore-cms/commit/5cc3937b6bc38293ec921a5cf00018b48b668dc6 • CWE-434: Unrestricted Upload of File with Dangerous Type •

CVE-2017-8868
https://notcve.org/view.php?id=CVE-2017-8868
10 May 2017 — acp/core/files.browser.php in flatCore 1.4.7 allows file deletion via directory traversal in the delete parameter to acp/acp.php. The risk might be limited to requests submitted through CSRF. Acp/core/files.browser.php en flatCore 1.4.7 permite la eliminación de archivos a través de directorio traversal en el parámetro delete a acp/acp.php. El riesgo podría estar limitado a las solicitudes enviadas a través de CSRF. • https://github.com/flatCore/flatCore-CMS/issues/30 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •