Elefant CMS是加拿大John de Plume个人开发者的一个简单 PHP 内容管理系统和 Web 框架。 Elefant CMS 1.3.12-RC 版本存在安全漏洞,远程攻击者利用该漏洞可执行代码注入攻击。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2017-20063 | 6.3 MEDIUM | Elefant CMS File Upload drop privileges management |
| CVE-2017-20062 | 5.0 MEDIUM | Elefant CMS cross-site request forgery |
| CVE-2017-20057 | 4.3 MEDIUM | Elefant CMS Persistent cross site scriting |
| CVE-2017-20058 | 4.3 MEDIUM | Elefant CMS Version Comparison Persistent cross site scriting |
| CVE-2017-20061 | 4.3 MEDIUM | Elefant CMS extended Reflected cross site scriting |
| CVE-2017-20059 | 3.5 LOW | Elefant CMS Title Persistent cross site scriting |
| CVE-2017-20060 | 3.5 LOW | Elefant CMS Blog Post Persistent cross site scriting |
No comments yet