quarter77/PPress-CMS_vulnerability_chain_details

quarter77/PPress-CMS_vulnerability_chain_details

Releases0
PPress-CMS vulnerability chain details

CVE History

CVEPublishedCVSS v3CVSS v2
8.8 HIGH

Hardcoded credentials in default configuration of PPress 0.0.9.

8 HIGH

An issue was discovered in PPress 0.0.9 allowing attackers to gain escilated privlidges via crafted session cookie.

8.8 HIGH

Server-side template injection (SSTI) vulnerability in PPress 0.0.9 allows attackers to execute arbitrary code via crafted themes.