📦 Mysiteforme

by Wangl1989

🔍 What is Mysiteforme?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-26136

CRITICAL CVSS 9.8 Mar 4, 2025

A SQL injection vulnerability in mysiteforme allows attackers to execute arbitrary SQL commands on the database. This affects all mysiteforme installations running versions before 2025.01.1, potential...

CVE-2024-57763

CRITICAL CVSS 9.1 Jan 15, 2025

This CVE describes a fastjson deserialization vulnerability in MSFM that allows remote code execution by sending malicious payloads to the system/table/addField endpoint. Attackers can exploit this to...

CVE-2024-57766

CRITICAL CVSS 9.1 Jan 15, 2025

This vulnerability allows remote code execution through fastjson deserialization in MSFM's table editing component. Attackers can exploit this to execute arbitrary code on affected systems. All system...

CVE-2024-57765

HIGH CVSS 7.5 Jan 15, 2025

This SQL injection vulnerability in MSFM allows attackers to execute arbitrary SQL commands through the s_name parameter in the table/list functionality. Attackers could potentially read, modify, or d...

CVE-2024-57762

HIGH CVSS 7.5 Jan 15, 2025

MSFM before version 2025.01.01 contains a deserialization vulnerability in its pom.xml configuration file that could allow remote code execution. This affects systems running vulnerable versions of MS...

CVE-2024-13138

MEDIUM CVSS 4.7 Jan 5, 2025

This vulnerability allows remote attackers to upload arbitrary files without restrictions in wangl1989 mysiteforme 1.0. Attackers can exploit this to upload malicious files like webshells or malware. ...

CVE-2024-13136

MEDIUM CVSS 6.3 Jan 5, 2025

This vulnerability allows remote attackers to execute arbitrary code through insecure deserialization in the rememberMeManager function of mysiteforme 1.0. Attackers can exploit this to gain unauthori...