This CPE summary could be partial or incomplete. Please contact us for a detailed listing.

Summary

Detail
Vendor Kliqqi First view 2018-04-22
Product Kliqqi Cms Last view 2021-09-15
Version Type Application
Update  
Edition  
Language  
Sofware Edition  
Target Software  
Target Hardware  
Other  

Activity : Overall

COMMON PLATFORM ENUMERATION: Repartition per Version

CPE Name Affected CVE
cpe:2.3:a:kliqqi:kliqqi_cms:3.5.2:*:*:*:*:*:*:* 2
cpe:2.3:a:kliqqi:kliqqi_cms:2.0.2:*:*:*:*:*:*:* 2
cpe:2.3:a:kliqqi:kliqqi_cms:3.0.0.5:*:*:*:*:*:*:* 1

Related : CVE

  Date Alert Description
9.8 2021-09-15 CVE-2020-21121

Pligg CMS 2.0.2 contains a time-based SQL injection vulnerability via the $recordIDValue parameter in the admin_update_module_widgets.php file.

8.8 2019-05-24 CVE-2016-10756

Kliqqi 3.0.0.5 allows CSRF with resultant Arbitrary File Upload because module.php?module=upload can be used to configure the uploading of .php files, and then modules/upload/upload_main.php can be used for the upload itself.

8.8 2018-05-24 CVE-2018-11405

Kliqqi 2.0.2 has CSRF in admin/admin_users.php.

9.8 2018-04-22 CVE-2017-17902

SQL Injection exists in Kliqqi CMS 3.5.2 via the randkey parameter of a new story at the pligg/story.php?title= URI.

5.4 2018-04-22 CVE-2017-17889

Kliqqi CMS 3.5.2 has XSS via a crafted group name in pligg/groups.php, a crafted Homepage string in a profile, or a crafted string in Tags or Description within pligg/submit.php.

CWE : Common Weakness Enumeration

%idName
40% (2) CWE-352 Cross-Site Request Forgery (CSRF)
40% (2) CWE-89 Improper Sanitization of Special Elements used in an SQL Command ('...
20% (1) CWE-79 Failure to Preserve Web Page Structure ('Cross-site Scripting')