lfdycms records
5 published records for vendor lfdycms.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-352 Cross-Site Request Forgery (CSRF)3
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
5 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
36Monitor | CVE-2018-12603Proof of concept | Cross-site request forgery (CSRF) vulnerability in admin.php in LFCMS 3.7.0 allows remote attackers to hijack the authentication of unspeciflfdycms · lfcms · CWE-352 | High8.8 | — | 3.5% | Jun 25, 2018 |
36Monitor | CVE-2018-12602Proof of concept | A CSRF vulnerability exists in LFCMS 3.7.0: users can be added arbitrarily.lfdycms · lfcms · CWE-352 | High8.8 | — | 3.0% | Jun 25, 2018 |
35Monitor | CVE-2018-20603No exploit | Lei Feng TV CMS (aka LFCMS) 3.8.6 allows admin.php?s=/Member/add.html CSRF.lfdycms · lei feng tv cms · CWE-352 | High8.8 | — | 0.5% | Dec 30, 2018 |
30Monitor | CVE-2018-20602No exploit | Lei Feng TV CMS (aka LFCMS) 3.8.6 allows full path disclosure via the /install.php?s=/1 URI.lfdycms · lei feng tv cms · CWE-200 | High7.5 | — | 1.3% | Dec 30, 2018 |
19Monitor | CVE-2018-20604No exploit | Lei Feng TV CMS (aka LFCMS) 3.8.6 allows Directory Traversal via crafted use of ..* in Template/edit/path URIs, as demonstrated by the adminlfdycms · lei feng tv cms · CWE-22 | Medium4.9 | — | 1.4% | Dec 30, 2018 |
- CVE-2018-1260336Monitor
Cross-site request forgery (CSRF) vulnerability in admin.php in LFCMS 3.7.0 allows remote attackers to hijack the authentication of unspecif
HighCVSS 8.8Proof of conceptEPSS 3%lfdycms · lfcmsJun 25, 2018
- CVE-2018-1260236Monitor
A CSRF vulnerability exists in LFCMS 3.7.0: users can be added arbitrarily.
HighCVSS 8.8Proof of conceptEPSS 3%lfdycms · lfcmsJun 25, 2018
- CVE-2018-2060335Monitor
Lei Feng TV CMS (aka LFCMS) 3.8.6 allows admin.php?s=/Member/add.html CSRF.
HighCVSS 8.8No exploitEPSS 1%lfdycms · lei feng tv cmsDec 30, 2018
- CVE-2018-2060230Monitor
Lei Feng TV CMS (aka LFCMS) 3.8.6 allows full path disclosure via the /install.php?s=/1 URI.
HighCVSS 7.5No exploitEPSS 1%lfdycms · lei feng tv cmsDec 30, 2018
- CVE-2018-2060419Monitor
Lei Feng TV CMS (aka LFCMS) 3.8.6 allows Directory Traversal via crafted use of ..* in Template/edit/path URIs, as demonstrated by the admin
MediumCVSS 4.9No exploitEPSS 1%lfdycms · lei feng tv cmsDec 30, 2018