CmsEasy是中国九州易通(CmsEasy)公司的一套用于创建响应式网站的内容管理系统(CMS)。 CmsEasy 7.7.7.9版本存在路径遍历漏洞,该漏洞源于函数deleteimg_action的参数imgname会导致路径遍历。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | CmsEasy | 7.7.7.9 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2025-1335 | 4.3 MEDIUM | CmsEasy file_admin.php deleteimg_action path traversal |
| CVE-2025-1341 | 3.7 LOW | PMWeb Setting weak password |
| CVE-2025-1332 | 2.4 LOW | FastCMS Template Menu menu cross site scripting |
No comments yet