Skip to content
Noroxi

bagesoft records

7 published records for vendor bagesoft.

All records

7 records
  • An issue was discovered in BageCMS 3.1.3.

    CriticalCVSS 9.8No exploitEPSS 1%

    bagesoft · bagecmsOct 11, 2018

  • BageCMS 3.1.3 has CSRF via upload/index.php?r=admini/admin/ownerUpdate to modify a user account.

    HighCVSS 8.8No exploitEPSS 1%

    bagesoft · bagecmsNov 26, 2018

  • In BageCMS 3.1.3, upload/index.php has a CSRF vulnerability that can be used to upload arbitrary files and get server privileges.

    HighCVSS 8.8No exploitEPSS 1%

    bagesoft · bagecmsNov 8, 2018

  • index.php?r=admini/admin/create in BageCMS V3.1.3 allows CSRF to add a background administrator account.

    HighCVSS 8.8No exploitEPSS 1%

    bagesoft · bagecmsJul 24, 2018

  • An issue was discovered in BageCMS 3.1.3.

    HighCVSS 7.5No exploitEPSS 2%

    bagesoft · bagecmsOct 11, 2018

  • CVE-2019-8421
    28Monitor

    upload/protected/modules/admini/views/post/index.php in BageCMS through 3.1.4 allows SQL Injection via the title or titleAlias parameter.

    HighCVSS 7.2No exploitEPSS 1%

    bagesoft · bagecmsFeb 17, 2019

  • A stored cross-site scripting (XSS) vulnerability in Bagecms v3.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted

    MediumCVSS 5.4No exploitEPSS 0%

    bagesoft · bagecmsJul 6, 2023