VendorsBaiCloud-cms Projectbaicloud-cms2.5.7
Vulnerabilities

BaiCloud-cms Project BaiCloud-cms 2.5.7

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2021-41729
BaiCloud-cms v2.5.7 is affected by an arbitrary file deletion vulnerability, which allows an attacker to delete arbitrary files on the server through /user/ppsave.php.
Published 2021-09-30 · Modified
9.1EPSS 0.010
CVE-2021-44302
BaiCloud-cms v2.5.7 was discovered to contain multiple SQL injection vulnerabilities via the tongji and baidu_map parameters in /user/ztconfig.php.
Published 2022-02-18 · Modified
8.8EPSS 0.011