leadscloud/EmpireCMS

leadscloud/EmpireCMS

Releases2
Frequency
Last Release
Stars6
帝国CMS

CVE History

CVEPublishedCVSS v3CVSS v2
9.8 CRITICAL

EmpireCMS v7.5 was discovered to contain a SQL injection vulnerability via the ftppassword parameter at SetEnews.php.

9.8 CRITICAL7.5 HIGH

EmpireCMS 7.5 has a SQL injection vulnerability in AdClass.php

9.8 CRITICAL7.5 HIGH

A remote code execution (RCE) in e/install/index.php of EmpireCMS 7.5 allows attackers to execute arbitrary PHP code via writing malicious code to the install file.

6.8 MEDIUM

An issue was discovered in EmpireCMS 7.0. There is a CSRF vulnerability that can add administrators via upload/e/admin/user/AddUser.php?enews=AddUser.