Latest pagekit pagekit Vulnerabilities

An issue in Pagekit pagekit v.1.0.18 alows a remote attacker to execute arbitrary code via thedownloadAction and updateAction functions in UpdateController.php
Pagekit pagekit=1.0.18
A file upload vulnerability exists in the storage feature of pagekit 1.0.18, which allows an attacker to upload malicious files
Pagekit pagekit=1.0.18
A cross-site scripting (XSS) vulnerability in Pagekit CMS v1.0.18 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Markdown text box under /blog/post/e...
Pagekit pagekit=1.0.18
pagekit all versions, as of 15-10-2021, is vulnerable to SQL Injection via Comment listing.
Pagekit pagekit<=1.0.18
In PageKit v1.0.18, a user can upload SVG files in the file upload portion of the CMS. These SVG files can contain malicious scripts. This file will be uploaded to the system and it will not be stripp...
Pagekit pagekit=1.0.18
A CSRF vulnerability in Pagekit 1.0.17 allows an attacker to upload an arbitrary file by removing the CSRF token from a request.
composer/pagekit/pagekit<=1.0.17
Pagekit pagekit=1.0.17
The Reset Password feature in Pagekit 1.0.17 gives a different response depending on whether the e-mail address of a valid user account is entered, which might make it easier for attackers to enumerat...
Pagekit pagekit=1.0.17
composer/pagekit/pagekit=1.0.17
Pagekit before 1.0.14 has a /user/login?redirect= open redirect vulnerability.
Pagekit pagekit<1.0.14
composer/pagekit/pagekit<1.0.14
Stored XSS in YOOtheme Pagekit 1.0.13 and earlier allows a user to upload malicious code via the picture upload feature. A user with elevated privileges could upload a photo to the system in an SVG fo...
Pagekit pagekit<=1.0.13
composer/pagekit/pagekit=1.0.13

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2024 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203