Vulnerabilities
Vulnerable Software
Otcms:  >> Otcms  >> 7.01  Security Vulnerabilities
Server-Side Request Forgery (SSRF) vulnerability exists in the AnnounContent of the /admin/read.php in OTCMS V7.66 and before. The vulnerability allows remote attackers to craft HTTP requests, without authentication, containing a URL pointing to internal services or any remote server
CVSS Score
7.5
EPSS Score
0.001
Published
2026-03-27
OtCMS <=V7.46 is vulnerable to Server-Side Request Forgery (SSRF) in /admin/read.php, which can Read system files arbitrarily.
CVSS Score
4.3
EPSS Score
0.003
Published
2025-01-17
A vulnerability, which was classified as critical, was found in OTCMS 7.01. Affected is an unknown function of the file /admin/ind_backstage.php. The manipulation of the argument sqlContent leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-247908.
CVSS Score
4.7
EPSS Score
0.001
Published
2023-12-13


Contact Us

Shodan ® - All rights reserved