Skip to content
Noroxi

otcms records

18 published records for vendor otcms.

All records

18 records
  • CVE-2023-3237
    39Monitor

    OTCMS hard-coded password

    CriticalCVSS 9.8No exploitEPSS 1%

    otcms · otcmsJun 14, 2023

  • CVE-2023-1797
    39Monitor

    OTCMS unrestricted upload

    CriticalCVSS 9.8No exploitEPSS 1%

    otcms · otcmsApr 2, 2023

  • CVE-2023-1634
    39Monitor

    OTCMS URL Parameter info_deal.php UseCurl server-side request forgery

    CriticalCVSS 9.8No exploitEPSS 1%

    otcms · otcmsMar 25, 2023

  • CVE-2023-3238
    39Monitor

    OTCMS server-side request forgery

    CriticalCVSS 9.8No exploitEPSS 1%

    otcms · otcmsJun 14, 2023

  • OTCMS 3.61 allows remote attackers to execute arbitrary PHP code via the accBackupDir parameter.

    HighCVSS 8.1No exploitEPSS 1%

    otcms · otcmsSep 23, 2018

  • CVE-2023-3239
    30Monitor

    OTCMS path traversal

    HighCVSS 7.5No exploitEPSS 1%

    otcms · otcmsJun 14, 2023

  • CVE-2023-3241
    30Monitor

    OTCMS path traversal

    HighCVSS 7.5No exploitEPSS 1%

    otcms · otcmsJun 14, 2023

  • Server-Side Request Forgery (SSRF) vulnerability exists in the AnnounContent of the /admin/read.php in OTCMS V7.66 and before.

    HighCVSS 7.5No exploitEPSS 1%

    otcms · otcmsMar 27, 2026

  • OTCMS v3.85 allows arbitrary PHP Code Execution because admin/sysCheckFile_deal.php blocks "into outfile" in a SELECT statement, but does no

    HighCVSS 7.2No exploitEPSS 2%

    otcms · otcmsOct 9, 2019

  • CVE-2023-6772
    28Monitor

    OTCMS ind_backstage.php sql injection

    HighCVSS 7.2No exploitEPSS 1%

    otcms · otcmsDec 13, 2023

  • CVE-2023-3240
    26Monitor

    OTCMS usersNews_deal.php path traversal

    MediumCVSS 6.5No exploitEPSS 1%

    otcms · otcmsJun 14, 2023

  • OTCMS v3.85 has CSRF in the admin/member_deal.php Admin Panel page, leading to creation of a new management group account, as demonstrated b

    MediumCVSS 6.5No exploitEPSS 1%

    otcms · otcmsOct 9, 2019

  • OTCMS 3.81 allows XSS via the mode parameter in an apiRun.php?mudi=autoRun request.

    MediumCVSS 6.1No exploitEPSS 1%

    otcms · otcmsJul 19, 2019

  • An issue was discovered in OTCMS 3.61.

    MediumCVSS 6.1No exploitEPSS 1%

    otcms · otcmsSep 16, 2018

  • An issue was discovered in OTCMS 3.61.

    MediumCVSS 6.1No exploitEPSS 1%

    otcms · otcmsSep 16, 2018

  • CVE-2018-8973
    24Monitor

    OTCMS 3.20 allows XSS by adding a keyword or link to an article, as demonstrated by an admin/keyWord_deal.php?mudi=add request.

    MediumCVSS 6.1No exploitEPSS 1%

    otcms · otcmsMar 24, 2018

  • CVE-2023-1635
    24Monitor

    OTCMS apiRun.php AutoRun cross site scripting

    MediumCVSS 6.1No exploitEPSS 1%

    otcms · otcmsMar 25, 2023

  • OtCMS <=V7.46 is vulnerable to Server-Side Request Forgery (SSRF) in /admin/read.php, which can Read system files arbitrarily.

    MediumCVSS 4.3No exploitEPSS 0%

    otcms · otcmsJan 17, 2025