CVEbuzz logo
This website displays data collected from external sources, and is not responsible for any aspect of it. Read more...

Security / vulnerability advisories for BageCMS 3.1.3

Titles listed in dictionary

CPE for product: cpe:2.3:a:bagesoft:bagecms:3.1.3:*:*:*:*:*:*:*

Showing 1-6 of 6
Maximal damage 7.2
Difficult to exploit
(other affected products) Published: Sun Feb 17 22:29:00 2019 UTC. Last Modified: Wed Feb 20 15:35:00 2019 UTC
CPE matches: cpe:2.3:a:bagesoft:bagecms:*:*:*:*:*:*:*:* && versionEndIncluding=3.1.4

Description

upload/protected/modules/admini/views/post/index.php in BageCMS through 3.1.4 allows SQL Injection via the title or titleAlias parameter.

Damage

Attack conditions

Damage and attack conditions obtained from CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H (CVSSv3)

Type of bug(s)

References

Maximal damage 8.8
Easy to exploit
(other affected products) Published: Mon Nov 26 07:29:00 2018 UTC. Last Modified: Mon Dec 31 21:16:00 2018 UTC
CPE matches: cpe:2.3:a:bagesoft:bagecms:3.1.3:*:*:*:*:*:*:*

Description

BageCMS 3.1.3 has CSRF via upload/index.php?r=admini/admin/ownerUpdate to modify a user account.

Damage

Attack conditions

Damage and attack conditions obtained from CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H (CVSSv3)

Type of bug(s)

References

Maximal damage 8.8
Easy to exploit
(other affected products) Published: Thu Nov 8 08:29:00 2018 UTC. Last Modified: Tue Dec 11 21:23:00 2018 UTC
CPE matches: cpe:2.3:a:bagesoft:bagecms:3.1.3:*:*:*:*:*:*:*

Description

In BageCMS 3.1.3, upload/index.php has a CSRF vulnerability that can be used to upload arbitrary files and get server privileges.

Damage

Attack conditions

Damage and attack conditions obtained from CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H (CVSSv3)

Type of bug(s)

References

Maximal damage 9.8
Very easy to exploit
(other affected products) Published: Thu Oct 11 21:01:00 2018 UTC. Last Modified: Wed Jun 26 08:15:00 2019 UTC
CPE matches: cpe:2.3:a:bagesoft:bagecms:3.1.3:*:*:*:*:*:*:*

Description

An issue was discovered in BageCMS 3.1.3. The attacker can execute arbitrary PHP code on the web server and can read any file on the web server via an index.php?r=admini/template/updateTpl&filename= URI.

Damage

Attack conditions

Damage and attack conditions obtained from CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H (CVSSv3)

Type of bug(s)

References

Medium damage 7.5
Very easy to exploit
(other affected products) Published: Thu Oct 11 21:01:00 2018 UTC. Last Modified: Thu Nov 29 21:38:00 2018 UTC
CPE matches: cpe:2.3:a:bagesoft:bagecms:3.1.3:*:*:*:*:*:*:*

Description

An issue was discovered in BageCMS 3.1.3. An attacker can delete any files and folders on the web server via an index.php?r=admini/template/batch&command=deleteFile&fileName= or index.php?r=admini/template/batch&command=deleteFolder&folderName=../ directory traversal URI.

Damage

Attack conditions

Damage and attack conditions obtained from CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N (CVSSv3)

Type of bug(s)

References

Maximal damage 8.8
Easy to exploit
(other affected products) Published: Tue Jul 24 16:29:00 2018 UTC. Last Modified: Tue Sep 18 18:06:00 2018 UTC
CPE matches: cpe:2.3:a:bagesoft:bagecms:3.1.3:*:*:*:*:*:*:*

Description

index.php?r=admini/admin/create in BageCMS V3.1.3 allows CSRF to add a background administrator account.

Damage

Attack conditions

Damage and attack conditions obtained from CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H (CVSSv3)

Type of bug(s)

References