VYPR

AeroCMS

by AeroCMS

CVEs (19)

  • CVE-2022-38305HigSep 13, 2022
    risk 0.57cvss 8.8epss 0.01

    AeroCMS v0.0.1 was discovered to contain an arbitrary file upload vulnerability via the component /admin/profile.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.

  • CVE-2022-46137HigDec 16, 2022
    risk 0.49cvss 7.5epss 0.01

    AeroCMS v0.0.1 is vulnerable to Directory Traversal. The impact is: obtain sensitive information (remote). The component is: AeroCMS v0.0.1.

  • CVE-2022-45329HigNov 29, 2022
    risk 0.49cvss 7.5epss 0.01

    AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability via the Search parameter. This vulnerability allows attackers to access database information.

  • CVE-2022-45331HigNov 22, 2022
    risk 0.49cvss 7.5epss 0.01

    AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability via the p_id parameter at \post.php. This vulnerability allows attackers to access database information.

  • CVE-2022-45330HigNov 22, 2022
    risk 0.49cvss 7.5epss 0.01

    AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability via the Category parameter at \category.php. This vulnerability allows attackers to access database information.

  • CVE-2022-46135HigDec 16, 2022
    risk 0.47cvss 7.2epss 0.01

    In AeroCms v0.0.1, there is an arbitrary file upload vulnerability at /admin/posts.php?source=edit_post , through which we can upload webshell and control the web server.

  • CVE-2022-46051HigDec 13, 2022
    risk 0.47cvss 7.2epss 0.01

    The approve parameter from the AeroCMS-v0.0.1 CMS system is vulnerable to SQL injection attacks.

  • CVE-2022-27061HigApr 8, 2022
    risk 0.47cvss 7.2epss 0.03

    AeroCMS v0.0.1 was discovered to contain an arbitrary file upload vulnerability via the Post Image function under the Admin panel. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.

  • CVE-2022-46059MedDec 13, 2022
    risk 0.42cvss 6.5epss 0.00

    AeroCMS v0.0.1 is vulnerable to Cross Site Request Forgery (CSRF).

  • CVE-2022-38812MedAug 31, 2022
    risk 0.42cvss 6.5epss 0.02

    AeroCMS 0.1.1 is vulnerable to SQL Injection via the author parameter.

  • CVE-2022-46061MedDec 13, 2022
    risk 0.40cvss 6.1epss 0.00

    AeroCMS v0.0.1 is vulnerable to ClickJacking.

  • CVE-2022-27063MedApr 8, 2022
    risk 0.40cvss 6.1epss 0.01

    AeroCMS v0.0.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability via view_all_comments.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Comments text field.

  • CVE-2023-29847MedApr 14, 2023
    risk 0.35cvss 5.4epss 0.00

    AeroCMS v0.0.1 was discovered to contain multiple stored cross-site scripting (XSS) vulnerabilities via the comment_author and comment_content parameters at /post.php. These vulnerabilities allow attackers to execute arbitrary web scripts or HTML via a crafted payload.

  • CVE-2022-46047MedDec 13, 2022
    risk 0.32cvss 4.9epss 0.01

    AeroCMS v0.0.1 is vulnerable to SQL Injection via the delete parameter.

  • CVE-2022-45536MedNov 22, 2022
    risk 0.32cvss 4.9epss 0.01

    AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability via the id parameter at \admin\post_comments.php. This vulnerability allows attackers to access database information.

  • CVE-2022-45535MedNov 22, 2022
    risk 0.32cvss 4.9epss 0.01

    AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability via the edit parameter at \admin\categories.php. This vulnerability allows attackers to access database information.

  • CVE-2022-45529MedNov 22, 2022
    risk 0.32cvss 4.9epss 0.01

    AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability via the post_category_id parameter at \admin\includes\edit_post.php. This vulnerability allows attackers to access database information.

  • CVE-2022-46058MedDec 13, 2022
    risk 0.31cvss 4.8epss 0.00

    AeroCMS v0.0.1 was discovered to contain a cross-site scripting (XSS) vulnerability via add_post.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Comments text field.

  • CVE-2022-27062MedApr 8, 2022
    risk 0.31cvss 4.8epss 0.01

    AeroCMS v0.0.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability via add_post.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Post Title text field.