Lucene search

K

Hashbrowncms Security Vulnerabilities

cve
cve

CVE-2020-6948

A remote code execution issue was discovered in HashBrown CMS through 1.3.3. Server/Entity/Deployer/GitDeployer.js has a Service.AppService.exec call that mishandles the URL, repository, username, and...

9.8CVSS

9.7AI Score

0.023EPSS

2020-01-13 07:15 PM
35
cve
cve

CVE-2020-6949

A privilege escalation issue was discovered in the postUser function in HashBrown CMS through 1.3.3. An editor user can change the password hash of an admin user's account, or otherwise reconfigure that...

8.8CVSS

8.9AI Score

0.001EPSS

2020-01-13 07:15 PM
30
cve
cve

CVE-2020-5840

An issue was discovered in HashBrown CMS before 1.3.2. Server/Entity/Resource/Connection.js allows an attacker to reach a parent directory via a crafted name or ID...

7.5CVSS

7.3AI Score

0.002EPSS

2020-01-06 06:15 PM
36