5 results (0.007 seconds)

CVSS: 7.2EPSS: 3%CPEs: 1EXPL: 2

SOY CMS 3.0.2 and earlier is affected by Remote Code Execution (RCE) using Unrestricted File Upload. Cross-Site Scripting(XSS) vulnerability that was used in CVE-2020-15183 can be used to increase impact by redirecting the administrator to access a specially crafted page. This vulnerability is caused by insecure configuration in elFinder. This is fixed in version 3.0.2.328. SOY CMS versiones 3.0.2 y anteriores, están afectadas por una Ejecución de Código Remota (RCE) usando una Carga de Archivos Sin Restricciones. • https://github.com/inunosinsi/soycms/issues/9 https://github.com/inunosinsi/soycms/pull/14 https://github.com/inunosinsi/soycms/pull/14/commits/e4ef00677ed52f9e5a5fcfcb56b797f5412b5d59 https://github.com/inunosinsi/soycms/security/advisories/GHSA-6r2f-p68g-m433 https://youtu.be/FWIDFNXmr9g • CWE-434: Unrestricted Upload of File with Dangerous Type •

CVSS: 10.0EPSS: 9%CPEs: 1EXPL: 3

SOY CMS 3.0.2.327 and earlier is affected by Unauthenticated Remote Code Execution (RCE). The allows remote attackers to execute any arbitrary code when the inquiry form feature is enabled by the service. The vulnerability is caused by unserializing the form without any restrictions. This was fixed in 3.0.2.328. SOY CMS versiones 3.0.2.327 y anteriores, están afectadas por una Ejecución de Código Remota (RCE) No Autenticado. • https://github.com/inunosinsi/soycms/issues/10 https://github.com/inunosinsi/soycms/pull/12/commits/a75642989132dd25f74a13194b27c0986c3de020 https://github.com/inunosinsi/soycms/security/advisories/GHSA-hrrx-m22r-p9jp https://www.youtube.com/watch?v=zAE4Swjc-GU&feature=youtu.be • CWE-502: Deserialization of Untrusted Data •

CVSS: 9.6EPSS: 1%CPEs: 2EXPL: 1

The SOY Inquiry component of SOY CMS is affected by Cross-site Request Forgery (CSRF) and Remote Code Execution (RCE). The vulnerability affects versions 2.0.0.3 and earlier of SOY Inquiry. This allows remote attackers to force the administrator to edit files once the administrator loads a specially crafted webpage. An administrator must be logged in for exploitation to be possible. This issue is fixed in SOY Inquiry version 2.0.0.4 and included in SOY CMS 3.0.2.328. • https://github.com/inunosinsi/soycms/pull/15 https://github.com/inunosinsi/soycms/security/advisories/GHSA-j2qw-747j-mfv4 https://youtu.be/ffvKH3gwyRE • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CWE-352: Cross-Site Request Forgery (CSRF) •

CVSS: 7.5EPSS: 0%CPEs: 12EXPL: 0

Directory traversal vulnerability in SOY CMS Ver.1.8.1 to Ver.1.8.12 allows authenticated attackers to read arbitrary files via shop_id. Una vulnerabilidad de salto de directorio en SOY CMS en versiones 1.8.1 a 1.8.12 permite a atacantes autenticados leer archivos arbitrarios mediante shop_id. • http://jvn.jp/en/jp/JVN51819749/index.html • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •

CVSS: 6.1EPSS: 0%CPEs: 1EXPL: 0

Cross-site scripting vulnerability in SOY CMS with installer 1.8.12 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. Vulnerabilidad Cross-Site Scripting (XSS) en SOY CMS con el instalador 1.8.12 y en versiones anteriores, permite a los atacantes inyectar scripts web o HTML arbitrarios utilizando vectores no especificados. • http://jvn.jp/en/jp/JVN51978169/index.html • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •