|
211261
|
6.1 |
MEDIUM
Network
|
jeesns
|
jeesns
|
A reflected cross-site scripting (XSS) vulnerability in the /newVersion component of Jeesns 1.4.2 allows attackers to execute arbitrary web scripts or HTML.
|
CWE-79
Cross-site Scripting
|
CVE-2020-19283
|
2024-11-21 14:09 |
2021-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211262
|
6.1 |
MEDIUM
Network
|
jeesns
|
jeesns
|
A reflected cross-site scripting (XSS) vulnerability in Jeesns 1.4.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the system error message's text field.
|
CWE-79
Cross-site Scripting
|
CVE-2020-19282
|
2024-11-21 14:09 |
2021-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211263
|
5.4 |
MEDIUM
Network
|
jeesns
|
jeesns
|
A stored cross-site scripting (XSS) vulnerability in the /manage/loginusername component of Jeesns 1.4.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the usernam…
|
CWE-79
Cross-site Scripting
|
CVE-2020-19281
|
2024-11-21 14:09 |
2021-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211264
|
8.8 |
HIGH
Network
|
jeesns
|
jeesns
|
Jeesns 1.4.2 contains a cross-site request forgery (CSRF) which allows attackers to escalate privileges and perform sensitive program operations.
|
CWE-352
Origin Validation Error
|
CVE-2020-19280
|
2024-11-21 14:09 |
2021-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211265
|
5.7 |
MEDIUM
Network
|
dswjcms_project
|
dswjcms
|
A cross-site request forgery (CSRF) in index.php/Dswjcms/User/tfAdd of Dswjcms 1.6.4 allows authenticated attackers to arbitrarily add administrator users.
|
CWE-352
Origin Validation Error
|
CVE-2020-19268
|
2024-11-21 14:09 |
2021-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211266
|
9.8 |
CRITICAL
Network
|
dswjcms_project
|
dswjcms
|
An issue in index.php/Dswjcms/Basis/resources of Dswjcms 1.6.4 allows attackers to execute arbitrary code via uploading a crafted PHP file.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-19267
|
2024-11-21 14:09 |
2021-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211267
|
6.1 |
MEDIUM
Network
|
dswjcms_project
|
dswjcms
|
A stored cross-site scripting (XSS) vulnerability in the index.php/Dswjcms/Site/articleList component of Dswjcms 1.6.4 allows attackers to execute arbitrary web scripts or HTML.
|
CWE-79
Cross-site Scripting
|
CVE-2020-19266
|
2024-11-21 14:09 |
2021-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211268
|
6.1 |
MEDIUM
Network
|
dswjcms_project
|
dswjcms
|
A stored cross-site scripting (XSS) vulnerability in the index.php/Dswjcms/Basis/links component of Dswjcms 1.6.4 allows attackers to execute arbitrary web scripts or HTML.
|
CWE-79
Cross-site Scripting
|
CVE-2020-19265
|
2024-11-21 14:09 |
2021-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211269
|
6.5 |
MEDIUM
Network
|
mipcms
|
mipcms
|
A cross-site request forgery (CSRF) in MipCMS v5.0.1 allows attackers to arbitrarily add users via index.php?s=/user/ApiAdminUser/itemAdd.
|
CWE-352
Origin Validation Error
|
CVE-2020-19264
|
2024-11-21 14:09 |
2021-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211270
|
8.8 |
HIGH
Network
|
mipcms
|
mipcms
|
A cross-site request forgery (CSRF) in MipCMS v5.0.1 allows attackers to arbitrarily escalate user privileges to administrator via index.php?s=/user/ApiAdminUser/itemEdit.
|
CWE-352
Origin Validation Error
|
CVE-2020-19263
|
2024-11-21 14:09 |
2021-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|