flexdotnetcms project records
2 published records for vendor flexdotnetcms project.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 1 · 50%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-434 Unrestricted Upload of File with Dangerous Type1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
2 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
57Plan | CVE-2020-27386Weaponized | An unrestricted file upload issue in FlexDotnetCMS before v1.5.9 allows an authenticated remote attacker to upload and execute arbitrary filflexdotnetcms project · flexdotnetcms · CWE-434 | High8.8 | — | 72.9% | Nov 12, 2020 |
33Monitor | CVE-2020-27385No exploit | Incorrect Access Control in the FileEditor (/Admin/Views/FileEditor/) in FlexDotnetCMS before v1.5.11 allows an authenticated remote attackeflexdotnetcms project · flexdotnetcms · CWE-22 | High8.1 | — | 1.8% | Nov 12, 2020 |
- CVE-2020-2738657Plan
An unrestricted file upload issue in FlexDotnetCMS before v1.5.9 allows an authenticated remote attacker to upload and execute arbitrary fil
HighCVSS 8.8WeaponizedEPSS 73%flexdotnetcms project · flexdotnetcmsNov 12, 2020
- CVE-2020-2738533Monitor
Incorrect Access Control in the FileEditor (/Admin/Views/FileEditor/) in FlexDotnetCMS before v1.5.11 allows an authenticated remote attacke
HighCVSS 8.1No exploitEPSS 2%flexdotnetcms project · flexdotnetcmsNov 12, 2020