VendorsBigTree CMSbigtree_cms4.2.16
Vulnerabilities

BigTree CMS Bigtree CMS 4.2.16

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2017-6914
CSRF exists in BigTree CMS 4.1.18 and 4.2.16 with the id parameter to the admin/ajax/users/delete/ page. A user can be deleted.
Published 2017-03-15 · Modified
7.1EPSS 0.004
CVE-2017-6917
CSRF exists in BigTree CMS 4.2.16 with the value parameter to the admin/settings/update/ page. The Colophon can be changed.
Published 2017-03-15 · Modified
4.3EPSS 0.004
CVE-2017-6918
CSRF exists in BigTree CMS 4.2.16 with the value[#][*] parameter to the admin/settings/update/ page. The Navigation Social can be changed.
Published 2017-03-15 · Modified
4.3EPSS 0.004