Skip to main content

Vendor archive

hashbrowncms CVEs

Beta · best-effort

3 CVEs tagged to vendor hashbrowncms1 Critical, 2 High, 0 Medium, 0 Low, 0 Unrated.

CVE-2020-6949

Published Jan 13, 2020

A privilege escalation issue was discovered in the postUser function in HashBrown CMS through 1.3.3. An editor user can change the password hash of an admin user's account, or oth…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-6948

Published Jan 13, 2020

A remote code execution issue was discovered in HashBrown CMS through 1.3.3. Server/Entity/Deployer/GitDeployer.js has a Service.AppService.exec call that mishandles the URL, repo…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-5840

Published Jan 6, 2020

An issue was discovered in HashBrown CMS before 1.3.2. Server/Entity/Resource/Connection.js allows an attacker to reach a parent directory via a crafted name or ID field.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-3 of 3 CVEsPage 1 of 1