kooboo_cms vulnerabilities
CVEs whose affected-version data names the kooboo_cms package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2021-36582Critical· 9.8In Kooboo CMS 2.1.1.0, it is possible to upload a remote shell (e.g., aspx) to the server and then call upon it to receive a reverse shell from the victim server
In Kooboo CMS 2.1.1.0, it is possible to upload a remote shell (e.g., aspx) to the server and then call upon it to receive a reverse shell from the victim server. The files are uploaded to /Content/Template/root/reverse-shell.aspx and ca…
▾ Midnightkooboo · kooboo_cmsEPSS 1.5%via NVD
CVE-2021-36581Critical· 9.8Kooboo CMS 2.1.1.0 is vulnerable to Insecure file upload
Kooboo CMS 2.1.1.0 is vulnerable to Insecure file upload. It is possible to upload any file extension to the server. The server does not verify the extension of the file and the tester was able to upload an aspx to the server.
▾ Midnightkooboo · kooboo_cmsEPSS 1.4%via NVD