Skip to main content

Vendor archive

earcms CVEs

Beta · best-effort

2 CVEs tagged to vendor earcms1 Critical, 1 High, 0 Medium, 0 Low, 0 Unrated.

CVE-2020-18912

Published Aug 29, 2023

An issue found in Earcms Ear App v.20181124 allows a remote attacker to execute arbitrary code via the uload/index-uplog.php.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-11756

Published Jul 30, 2017

In Earcms Ear Music through 4.1 build 20170710, remote authenticated users can execute arbitrary PHP code by changing the allowable music-upload extensions to include .php in addi…

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort
Showing 1-2 of 2 CVEsPage 1 of 1