Vulnerabilities > Feifeicms > High

DATE CVE VULNERABILITY TITLE RISK
2023-06-27 CVE-2020-18418 Cross-Site Request Forgery (CSRF) vulnerability in Feifeicms 4.1.190209
A Cross site request forgery (CSRF) vulnerability was discovered in FeiFeiCMS v4.1.190209, which allows attackers to create administrator accounts via /index.php?s=Admin-Admin-Insert.
network
low complexity
feifeicms CWE-352
8.8
2019-02-17 CVE-2019-8412 Path Traversal vulnerability in Feifeicms 4.0.181010
FeiFeiCms 4.0.181010 on Windows allows remote attackers to read or delete arbitrary files via index.php?s=Admin-Data-Down-id-..\ or index.php?s=Admin-Data-Del-id-..\ directory traversal.
network
low complexity
feifeicms CWE-22
8.8