Vulnerabilities > Kitesky > Kitecms > 1.1.1

DATE CVE VULNERABILITY TITLE RISK
2022-04-21 CVE-2022-28445 Files or Directories Accessible to External Parties vulnerability in Kitesky Kitecms 1.1.1
KiteCMS v1.1.1 was discovered to contain an arbitrary file read vulnerability via the background management module.
network
low complexity
kitesky CWE-552
4.0
2021-08-12 CVE-2021-31731 Path Traversal vulnerability in Kitesky Kitecms 1.1.1
A directory traversal issue in KiteCMS 1.1.1 allows remote administrators to overwrite arbitrary files via ../ in the path parameter to index.php/admin/Template/fileedit, with PHP code in the html parameter.
network
low complexity
kitesky CWE-22
5.5