Releases1
Frequency
Last Release
Stars41
KiteCMS系统基于Thinkphp 5.1.37 版本开发,真正的开源免费,可以用于商业目的,无需任何授权。后续会不断的完善优化系统,开发更多实用的模块,插件,模板。官方QQ群:3337800 。后台管理演示地址: http://test.19981.com/admin 账号密码 admin/admin

CVE History

CVEPublishedCVSS v3CVSS v2
9.8 CRITICAL

Permissions vulnerability found in KiteCMS allows a remote attacker to execute arbitrary code via the upload file type.

7.2 HIGH

File Upload vulnerability found in KiteCMS v.1.1 allows a remote attacker to execute arbitrary code via the uploadFile function.

6.1 MEDIUM

Cross Site Scripting vulnerability found in KiteCMS v.1.1 allows a remote attacker to execute arbitrary code via the comment parameter.

6.1 MEDIUM

Cross Site Scripting vulnerability found in KiteCMS v.1.1 allows a remote attacker to execute arbitrary code via the registering user parameter.

7.5 HIGH

Incorrect Access Control issue discovered in KiteCMS 1.1 allows remote attackers to view sensitive information via path in application URL.

8.8 HIGH6.8 MEDIUM

A cross-site request forgery (CSRF) in KiteCMS V1.1 allows attackers to arbitrarily add an administrator account.

7.8 HIGH6.8 MEDIUM

An arbitrary file upload vulnerability in /admin/upload/uploadfile of KiteCMS V1.1 allows attackers to getshell via a crafted PHP file.

6.5 MEDIUM5.5 MEDIUM

A directory traversal issue in KiteCMS 1.1.1 allows remote administrators to overwrite arbitrary files via ../ in the path parameter to index.php/admin/Template/fileedit, with PHP code in the html parameter.