VendorsBigTree CMSbigtree_cms4.2.23
Vulnerabilities

BigTree CMS Bigtree CMS 4.2.23

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2018-17341
BigTree 4.2.23 on Windows, when Advanced or Simple Rewrite routing is enabled, allows remote attackers to bypass authentication via a ..\ substring, as demonstrated by a launch.php?bigtree_htaccess_url=admin/images/..\ URI.
Published 2018-09-23 · Modified
8.1EPSS 0.019
CVE-2018-17030
BigTree CMS 4.2.23 allows remote authenticated users, if possessing privileges to set hooks, to execute arbitrary code via /core/admin/auto-modules/forms/process.php.
Published 2018-09-14 · Modified
7.5EPSS 0.023
CVE-2018-18308
In the 4.2.23 version of BigTree, a Stored XSS vulnerability has been discovered in /admin/ajax/file-browser/upload/ (aka the image upload area).
Published 2018-10-16 · Modified
6.11 PoCEPSS 0.036