
glFusion/glfusion
CVE History
| CVE | Published | CVSS v3 | CVSS v2 |
|---|---|---|---|
| 4.3 MEDIUM | 4.3 MEDIUM | ||
glFusion CMS 1.7.9 is affected by a Cross Site Request Forgery (CSRF) vulnerability in /public_html/admin/plugins/bad_behavior2/blacklist.php. Using the CSRF vulnerability to trick the administrator to click, an attacker can add a blacklist. | |||
| 9.8 CRITICAL | 7.5 HIGH | ||
glFusion CMS 1.7.9 is affected by an access control vulnerability via /public_html/users.php. | |||
| 9.1 CRITICAL | 6.4 MEDIUM | ||
glFusion CMS v1.7.9 is affected by an arbitrary user impersonation vulnerability in /public_html/comment.php. The attacker can complete the attack remotely without interaction. | |||
| 5.3 MEDIUM | 5 MEDIUM | ||
glFusion CMS v1.7.9 is affected by an arbitrary user registration vulnerability in /public_html/users.php. An attacker can register with the mailbox of any user. When users want to register, they will find that the mailbox has been occupied. | |||