VendorsOFCMS Projectofcms1.1.2
Vulnerabilities

OFCMS Project OFCMS 1.1.2

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-2024-34256
OFCMS V1.1.2 is vulnerable to SQL Injection via the new table function.
Published 2024-05-14 · Analyzed
9.8EPSS 0.007
CVE-2024-48235
An issue in ofcms 1.1.2 allows a remote attacker to execute arbitrary code via the save method of the TemplateController.java file.
Published 2024-10-25 · Analyzed
6.5EPSS 0.007
CVE-2024-48236
An issue in ofcms 1.1.2 allows a remote attacker to execute arbitrary code via the FileOutputStream function in the write String method of the ofcms-admin\src\main\java\com\ofsoft\cms\core\uitle\FileUtils.java file
Published 2024-10-25 · Analyzed
6.5EPSS 0.007
CVE-2024-9411
OFCMS add.json add cross site scripting
Published 2024-10-01 · Analyzed
5.3EPSS 0.004