VendorsflatCoreflatcore-cms1.4.6
Vulnerabilities

flatCore flatCore-cms 1.4.6

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-2017-7878
SQL Injection vulnerability in flatCore version 1.4.6 allows an attacker to read and write to the users database.
Published 2017-04-14 · Modified
9.8EPSS 0.010
CVE-2017-7877
CSRF vulnerability in flatCore version 1.4.6 allows remote attackers to modify CMS configurations.
Published 2017-04-14 · Modified
8.8EPSS 0.009
CVE-2017-7879
SQL Injection vulnerability in flatCore version 1.4.6 allows an attacker to read the content database.
Published 2017-04-14 · Modified
7.5EPSS 0.010
CVE-2017-1000428
flatCore-CMS 1.4.6 is vulnerable to reflected XSS in user_management.php due to the use of $_SERVER['PHP_SELF'] to build links and a stored XSS in the admin log panel by specifying a malformed User-Agent string.
Published 2018-01-10 · Modified
6.1EPSS 0.008