« Back to list

Elefantcms

Elefantcms Elefant: vulnerabilities and CVEs

Elefantcms Elefant has 4 published vulnerabilities, 0 of them in the last 12 months. 3 are rated critical and 0 are listed by CISA as actively exploited.

CVEs4
Last 12 months0
Critical3
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2024-50590High (7.8)0.19%—Nov 8, 2024
Attackers with local access to the medical office computer can escalate their Windows user privileges to "NT AUTHORITY\SYSTEM" by overwriting one of two Elefant service binaries with weak permissions. The default…
CVE-2024-50588Critical (9.8)0.70%—Nov 8, 2024
An unauthenticated attacker with access to the local network of the medical office can use known default credentials to gain remote DBA access to the Elefant Firebird database. The data in the database includes patient…
CVE-2018-16975Critical (9.8)3.7%—Sep 12, 2018
An issue was discovered in Elefant CMS before 2.0.7. There is a PHP Code Execution Vulnerability in /designer/add/stylesheet.php by using a .php extension in the New Stylesheet Name field in conjunction with <?php…
CVE-2018-16974Critical (9.8)3.6%—Sep 12, 2018
An issue was discovered in Elefant CMS before 2.0.7. There is a PHP Code Execution Vulnerability in apps/filemanager/upload/drop.php by using /filemanager/api/rm/.htaccess to remove the .htaccess file, and then using a…

Other products by Elefantcms