Latest popojicms popojicms Vulnerabilities

PopojiCMS version 2.0.1 is vulnerable to remote command execution in the Meta Social field.
Popojicms Popojicms=2.0.1
PopojiCMS Web Config install.php cross site scripting
=2.0.1
PopojiCMS v2.0.1 backend plugin function has a file upload vulnerability.
Popojicms Popojicms=2.0.1
Cross Site Request Forgery (CSRF) vulnerability exist in PopojiCMS 2.0.1 in po-admin/route.php?mod=user&act=multidelete.
Popojicms Popojicms=2.0.1
Directory Traversal vulnerability exists in PopojiCMS 2.0.1 via the id parameter in admin.php.
Popojicms Popojicms=2.0.1
Popojicms Popojicms=1.2
PopojiCMS 2.0.1 allows refer= Open Redirection.
Popojicms Popojicms=2.0.1
po-admin/route.php?mod=post&act=edit in PopojiCMS 2.0.1 allows post[1][content]= stored XSS.
Popojicms Popojicms=2.0.1
An issue was discovered in PopojiCMS v2.0.1. It has CSRF via the po-admin/route.php?mod=user&act=addnew URI, as demonstrated by adding a level=1 account, a similar issue to CVE-2018-18935.
Popojicms Popojicms=2.0.1
An issue was discovered in PopojiCMS v2.0.1. admin_library.php allows remote attackers to delete arbitrary files via directory traversal in the po-admin/route.php?mod=library&act=delete id parameter.
Popojicms Popojicms=2.0.1
An issue was discovered in PopojiCMS v2.0.1. admin_component.php is exploitable via the po-admin/route.php?mod=component&act=addnew URI by using the fupload parameter to upload a ZIP file containing a...
Popojicms Popojicms=2.0.1
An issue was discovered in PopojiCMS v2.0.1. It has CSRF via the po-admin/route.php?mod=component&act=addnew URI, as demonstrated by adding a level=1 account.
Popojicms Popojicms=2.0.1

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2024 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203