Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
flatcore flatcore 1.4.6 vulnerabilities and exploits
(subscribe to this query)
4.3
CVSSv2
CVE-2017-1000428
flatCore-CMS 1.4.6 is vulnerable to reflected XSS in user_management.php due to the use of $_SERVER['PHP_SELF'] to build links and a stored XSS in the admin log panel by specifying a malformed User-Agent string.
Flatcore Flatcore-cms 1.4.6
4.3
CVSSv2
CVE-2017-9451
Cross site scripting (XSS) vulnerability in pages.edit_form.php in flatCore 1.4.6 allows remote malicious users to inject arbitrary JavaScript via the PATH_INFO in an acp.php URL, due to use of unsanitized $_SERVER['PHP_SELF'] to generate URLs.
Flatcore Flatcore 1.4.6
6.8
CVSSv2
CVE-2017-7877
CSRF vulnerability in flatCore version 1.4.6 allows remote malicious users to modify CMS configurations.
Flatcore Flatcore-cms 1.4.6
7.5
CVSSv2
CVE-2017-7878
SQL Injection vulnerability in flatCore version 1.4.6 allows an malicious user to read and write to the users database.
Flatcore Flatcore-cms 1.4.6
5
CVSSv2
CVE-2017-7879
SQL Injection vulnerability in flatCore version 1.4.6 allows an malicious user to read the content database.
Flatcore Flatcore-cms 1.4.6
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-4956
validation
CVE-2024-35221
remote attackers
CVE-2023-30309
CVE-2024-36112
CVE-2024-23109
CVE-2023-43850
stored XSS
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started