Security
Headlines
HeadlinesLatestCVEs

Tag

#php

CVE-2020-18416: Bug: Jymusic V2.0.0 CSRF · Issue #1 · dtorp06/jymusic

An cross site request forgery (CSRF) vulnerability discovered in Jymusic v2.0.0.,that allows attackers to execute arbitrary code via /admin.php?s=/addons/config.html&id=6 to modify payment information.

CVE
#csrf#vulnerability#git#php
CVE-2020-18410: Bug: ChaojiCMS V2.18 XSS #6 · Issue #6 · GodEpic/chaojicms

A stored cross site scripting (XSS) vulnerability in /index.php?admin-master-article-edit of Chaoji CMS v2.18 that allows attackers to obtain administrator privileges.

CVE-2020-18413: Bug: ChaojiCMS V2.18 XSS #5 · Issue #5 · GodEpic/chaojicms

Stored cross site scripting (XSS) vulnerability in /index.php?admin-master-navmenu-add of Chaoji CMS v2.18 that allows attackers to execute arbitrary code.

CVE-2020-18418: Vulnerability-detection/feifeicms/FeiFeiCMS_4.1_csrf.doc at master · GodEpic/Vulnerability-detection

A Cross site request forgery (CSRF) vulnerability was discovered in FeiFeiCMS v4.1.190209, which allows attackers to create administrator accounts via /index.php?s=Admin-Admin-Insert.

MyBB Favicon 1.0 Cross Site Scripting

MyBB Favicon plugin version 1.0 suffers from a cross site scripting vulnerability.

Job Board 1.0 Shell Upload

Job Board version 1.0 suffers from a remote shell upload vulnerability.

PrestaShop Winbiz Payment Improper Limitation

PrestaShop Winbiz Payment module suffers from an improper limitation of a Pathname to a restricted directory.

Xenforo 2.2.13 Cross Site Scripting

Xenforo version 2.2.13 suffers from a persistent cross site scripting vulnerability.

CVE-2021-30205: dzzoffice 2.02.1_SC_UTF8 exists Unauthorized access vulnerability · Issue #184 · zyx0814/dzzoffice

Incorrect access control in the component /index.php?mod=system&op=orgtree of dzzoffice 2.02.1_SC_UTF8 allows unauthenticated attackers to browse departments and usernames.

CVE-2021-30203: dzzoffice 2.02.1_SC_UTF8 exists a XSS vulnerability · Issue #183 · zyx0814/dzzoffice

A reflected cross-site scripting (XSS) vulnerability in the zero parameter of dzzoffice 2.02.1_SC_UTF8 allows attackers to execute arbitrary web scripts or HTML.