Vulnerabilities
Vulnerable Software
Feehi:  >> Feehi Cms  >> 2.1.1  Security Vulnerabilities
A Host Header Injection vulnerability in Feehi CMS 2.1.1 may allow an attacker to spoof a particular header. This can be exploited by abusing password reset emails.
CVSS Score
6.1
EPSS Score
0.005
Published
2022-09-14
A stored cross-site scripting (XSS) vulnerability in /index.php?r=site%2Fsignup of Feehi CMS v2.1.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the username field.
CVSS Score
5.4
EPSS Score
0.011
Published
2022-07-28
An arbitrary file upload vulnerability in the Advertising Management module of Feehi CMS v2.1.1 allows attackers to execute arbitrary code via a crafted PHP file.
CVSS Score
8.8
EPSS Score
0.002
Published
2022-07-27
Feehi CMS 2.1.1 is affected by a Server-side request forgery (SSRF) vulnerability. When the user modifies the HTTP Referer header to any url, the server can make a request to it.
CVSS Score
9.1
EPSS Score
0.002
Published
2021-05-24


Contact Us

Shodan ® - All rights reserved