VendorsBlackCat CMSblackcat_cms1.2
Vulnerabilities

BlackCat CMS Blackcat CMS 1.2

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5CVEs
CVE-2017-14050
In BlackCat CMS 1.2, backend/addons/install.php allows remote authenticated users to execute arbitrary PHP code via a ZIP archive that contains a .php file.
Published 2017-08-31 · Modified
8.8EPSS 0.012
CVE-2017-14048
BlackCat CMS 1.2 allows remote authenticated users to inject arbitrary PHP code into info.php via a crafted new_modulename parameter to backend/addons/ajax_create.php. NOTE: this can be exploited via CSRF.
Published 2017-08-31 · Modified
8.8EPSS 0.006
CVE-2017-13670
In BlackCat CMS 1.2, remote authenticated users can upload any file via the media upload function in backend/media/ajax_upload.php, as demonstrated by a ZIP archive that contains a .php file.
Published 2017-08-31 · Modified
6.5EPSS 0.008
CVE-2017-9609
Cross-site scripting (XSS) vulnerability in Blackcat CMS 1.2 allows remote authenticated users to inject arbitrary web script or HTML via the map_language parameter to backend/pages/lang_settings.php.
Published 2017-07-17 · Modified
5.4EPSS 0.015
CVE-2017-14049
In BlackCat CMS 1.2, backend/settings/ajax_save_settings.php allows remote authenticated users to conduct XSS attacks via the Website header or Website footer field.
Published 2017-08-31 · Modified
5.4EPSS 0.006