Hansuncms ProjectCVEs & Vulnerabilities
2 CVEs affecting Hansuncms Project products, tracked from the National Vulnerability Database, with CVSS/EPSS scores and exploitation status.
2 CVEs→ All vendors
Most Affected Products
hansuncms 2
CVE-2023-43899CRITICAL
hansun CMS v1.0 was discovered to contain a SQL injection vulnerability via the component /ajax/ajax_login.ashx.
10 Oct 2023
9.8
CVSS
CVE-2023-2245MEDIUM
A vulnerability was found in hansunCMS 1.4.3. It has been declared as critical. This vulnerability affects unknown code of the file /ueditor/net/controller.ashx?action=catchimage. The manipulation leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-227230 is the identifier assigned to this vulnerability.
22 Apr 2023
6.3
CVSS
← PrevPage 1 / 1Next →