Skip to content
Noroxi

rpcms records

7 published records for vendor rpcms.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
0%
Median publish → KEV
No record has entered KEV

Records by year

  1. 21
  2. 22
  3. 23

Bar: total · dark part: CISA KEV.

All records

7 records
  • In RPCMS v1.8 and below, attackers can interact with API and change variable "role" to "admin" to achieve admin user registration.

    HighCVSS 8.8No exploitEPSS 1%

    rpcms · rpcmsJul 26, 2021

  • RPCMS v3.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) which allows attackers to arbitrarily add an administrator accoun

    HighCVSS 8.8No exploitEPSS 0%

    rpcms · rpcmsOct 13, 2022

  • RPCMS v3.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) which allows attackers to arbitrarily change the password of any

    MediumCVSS 6.5No exploitEPSS 0%

    rpcms · rpcmsOct 13, 2022

  • RPCMS v3.0.2 was discovered to contain a reflected cross-site scripting (XSS) vulnerability in the Search function.

    MediumCVSS 6.1Proof of conceptEPSS 1%

    rpcms · rpcmsOct 13, 2022

  • In RPCMS v1.8 and below, the "nickname" variable is not properly sanitized before being displayed on page.

    MediumCVSS 5.4No exploitEPSS 1%

    rpcms · rpcmsJul 26, 2021

  • In RPCMS v1.8 and below, the "nickname" variable is not properly sanitized before being displayed on page.

    MediumCVSS 5.4No exploitEPSS 1%

    rpcms · rpcmsJul 26, 2021

  • A cross-site scripting (XSS) vulnerability in the component /logs/dopost.html in RPCMS v3.5.5 allows attackers to execute arbitrary web scri

    MediumCVSS 5.4No exploitEPSS 0%

    rpcms · rpcmsDec 14, 2023