Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
By Recent Activity
74cms vulnerabilities and exploits
(subscribe to this query)
5.5
CVSSv2
CVE-2018-20519
An issue was discovered in 74cms v4.2.111. It allows remote authenticated users to read or modify arbitrary resumes by changing a job-search intention, as demonstrated by the index.php?c=Personal&a=ajax_save_basic pid parameter....
74cms 74cms 4.2.111
4.3
CVSSv2
CVE-2018-20454
An issue was discovered in 74cms v4.2.111. upload/index.php?c=resume&a=resume_list has XSS via the key parameter....
74cms 74cms 4.2.111
7.5
CVSSv2
CVE-2019-10684
Application/Admin/Controller/ConfigController.class.php in 74cms v5.0.1 allows remote attackers to execute arbitrary PHP code via the index.php?m=Admin&c=config&a=edit site_domain parameter....
74cms 74cms 5.0.1
7.5
CVSSv2
CVE-2020-29279
PHP remote file inclusion in the assign_resume_tpl method in Application/Common/Controller/BaseController.class.php in 74CMS before 6.0.48 allows remote code execution....
74cms 74cms
6.8
CVSSv2
CVE-2019-11374
74CMS v5.0.1 has a CSRF vulnerability to add a new admin user via the index.php?m=Admin&c=admin&a=add URI....
74cms 74cms 5.0.1
1 EDB exploit available
6.5
CVSSv2
CVE-2019-17612
An issue was discovered in 74CMS v5.2.8. There is a SQL Injection generated by the _list method in the Common/Controller/BackendController.class.php file via the index.php?m=Admin&c=Ad&a=category sort parameter....
74cms 74cms 5.2.8
7.5
CVSSv2
CVE-2020-35339
In 74cms version 5.0.1, there is a remote code execution vulnerability in /Application/Admin/Controller/ConfigController.class.php and /ThinkPHP/Common/functions.php where attackers can obtain server permissions and control the server....
74cms 74cms 5.0.1
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
XXE
CVE-2021-21973
mass assignment
CVE-2021-1396
CVE-2018-19518
CVE-2020-28599
deserialization
CVE-2021-1230
CVE-2021-26681