Vendorsbaijiacms Projectbaijiacms4.1.4
Vulnerabilities

baijiacms Project baijiacms 4.1.4

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2022-38931
A Server-Side Request Forgery (SSRF) in fetch_net_file_upload function of baijiacmsV4 v4.1.4 allows remote attackers to force the application to make arbitrary requests via injection of arbitrary URLs into the url parameter.
Published 2022-09-20 · Modified
8.8EPSS 0.013
CVE-2021-33396
Cross Site Request Forgery (CSRF) vulnerability in baijiacms 4.1.4, allows attackers to change the password or other information of an arbitrary account via index.php.
Published 2023-02-15 · Modified
6.5EPSS 0.003