Vulnerabilities > Baicloud CMS Project

DATE CVE VULNERABILITY TITLE RISK
2022-02-19 CVE-2021-44302 SQL Injection vulnerability in Baicloud-Cms Project Baicloud-Cms 2.5.7
BaiCloud-cms v2.5.7 was discovered to contain multiple SQL injection vulnerabilities via the tongji and baidu_map parameters in /user/ztconfig.php.
network
low complexity
baicloud-cms-project CWE-89
8.8
2021-09-30 CVE-2021-41729 Missing Authorization vulnerability in Baicloud-Cms Project Baicloud-Cms 2.5.7
BaiCloud-cms v2.5.7 is affected by an arbitrary file deletion vulnerability, which allows an attacker to delete arbitrary files on the server through /user/ppsave.php.
network
low complexity
baicloud-cms-project CWE-862
critical
9.1