| CVE-2024-42718 |
BDSA-2024-10902 |
Medium |
Dec 26, 2025 |
A path traversal vulnerability in Croogo CMS 4.0.7 allows remote attackers to read arbitrary files via a specially crafted path in the 'edit-file' para
more...
A path traversal vulnerability in Croogo CMS 4.0.7 allows remote attackers to read arbitrary files via a specially crafted path in the 'edit-file' parameter.
less...
|
4.0.7, 4.0.6, 4.0.5, 4.0.4, 4.0.3, 4.0.2, 3.0.7, 4.0.1, 1.3.6, 1.4.6
|
| BDSA-2024-4641 |
|
Medium |
Jul 23, 2024 |
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability classified as critical has been found in Croogo up to 4.0.7. This affects an unknown part of the file `
more...
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability classified as critical has been found in Croogo up to 4.0.7. This affects an unknown part of the file `admin/settings/settings/prefix/Theme` of the component `Setting Handler`. The manipulation of the argument Content-Type leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-271053 was assigned to this vulnerability.
NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
**Note: CVE details have been utilized in generating this advisory. The details of the vulnerability have not been independently verified by BlackDuck CyRC.**
less...
|
|
| BDSA-2021-4038 |
|
High |
Jan 18, 2022 |
Croogo contains a stored cross-site scripting (XSS) vulnerability. An attacker can exploit this in order to execute malicious JavaScript code in a vict
more...
Croogo contains a stored cross-site scripting (XSS) vulnerability. An attacker can exploit this in order to execute malicious JavaScript code in a victim's instance of Croogo, which could be used to steal session tokens, cookies, or other sensitive information.
less...
|
|
| BDSA-2021-4037 |
|
High |
Jan 18, 2022 |
Croogo contains a stored cross-site scripting (XSS) vulnerability. An attacker can exploit this in order to execute malicious JavaScript code in a vict
more...
Croogo contains a stored cross-site scripting (XSS) vulnerability. An attacker can exploit this in order to execute malicious JavaScript code in a victim's browser, which could be used to steal session tokens, cookies, or other sensitive information.
less...
|
|
| BDSA-2021-4036 |
|
High |
Jan 18, 2022 |
Croogo contains a stored cross-site scripting (XSS) vulnerability. An attacker can exploit this in order to execute malicious JavaScript code in a vict
more...
Croogo contains a stored cross-site scripting (XSS) vulnerability. An attacker can exploit this in order to execute malicious JavaScript code in a victim's browser, which could be used to steal session tokens, cookies, or other sensitive information.
less...
|
|
| BDSA-2021-4035 |
|
High |
Jan 18, 2022 |
Croogo contains a stored cross-site scripting (XSS) vulnerability. An attacker can exploit this in order to execute malicious JavaScript code in a vict
more...
Croogo contains a stored cross-site scripting (XSS) vulnerability. An attacker can exploit this in order to execute malicious JavaScript code in a victim's instance of Croogo, which could be used to steal session tokens, cookies, or other sensitive information.
less...
|
|
| BDSA-2021-3669 |
|
Medium |
Dec 07, 2021 |
Croogo is vulnerable to remote code execution (RCE) due to unsafe file upload functionality. An authenticated attacker with administrator credentials c
more...
Croogo is vulnerable to remote code execution (RCE) due to unsafe file upload functionality. An authenticated attacker with administrator credentials could upload, and execute, arbitrary PHP scripts via the "Attachments" feature of the File Manager component.
less...
|
|