|
211371
|
5.4 |
MEDIUM
Network
|
jeesns
|
jeesns
|
A stored cross-site scripting (XSS) vulnerability in the /localhost/u component of Jeesns 1.4.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in a private message.
|
CWE-79
Cross-site Scripting
|
CVE-2020-19288
|
2024-11-21 14:09 |
2021-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211372
|
5.4 |
MEDIUM
Network
|
jeesns
|
jeesns
|
A stored cross-site scripting (XSS) vulnerability in the /group/post component of Jeesns 1.4.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the title.
|
CWE-79
Cross-site Scripting
|
CVE-2020-19287
|
2024-11-21 14:09 |
2021-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211373
|
5.4 |
MEDIUM
Network
|
jeesns
|
jeesns
|
A stored cross-site scripting (XSS) vulnerability in the /question/detail component of Jeesns 1.4.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the source field…
|
CWE-79
Cross-site Scripting
|
CVE-2020-19286
|
2024-11-21 14:09 |
2021-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211374
|
5.4 |
MEDIUM
Network
|
jeesns
|
jeesns
|
A stored cross-site scripting (XSS) vulnerability in the /group/apply component of Jeesns 1.4.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the Name text field.
|
CWE-79
Cross-site Scripting
|
CVE-2020-19285
|
2024-11-21 14:09 |
2021-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211375
|
5.4 |
MEDIUM
Network
|
jeesns
|
jeesns
|
A stored cross-site scripting (XSS) vulnerability in the /group/comment component of Jeesns 1.4.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the group comments…
|
CWE-79
Cross-site Scripting
|
CVE-2020-19284
|
2024-11-21 14:09 |
2021-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211376
|
6.1 |
MEDIUM
Network
|
jeesns
|
jeesns
|
A reflected cross-site scripting (XSS) vulnerability in the /newVersion component of Jeesns 1.4.2 allows attackers to execute arbitrary web scripts or HTML.
|
CWE-79
Cross-site Scripting
|
CVE-2020-19283
|
2024-11-21 14:09 |
2021-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211377
|
6.1 |
MEDIUM
Network
|
jeesns
|
jeesns
|
A reflected cross-site scripting (XSS) vulnerability in Jeesns 1.4.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the system error message's text field.
|
CWE-79
Cross-site Scripting
|
CVE-2020-19282
|
2024-11-21 14:09 |
2021-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211378
|
5.4 |
MEDIUM
Network
|
jeesns
|
jeesns
|
A stored cross-site scripting (XSS) vulnerability in the /manage/loginusername component of Jeesns 1.4.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the usernam…
|
CWE-79
Cross-site Scripting
|
CVE-2020-19281
|
2024-11-21 14:09 |
2021-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211379
|
8.8 |
HIGH
Network
|
jeesns
|
jeesns
|
Jeesns 1.4.2 contains a cross-site request forgery (CSRF) which allows attackers to escalate privileges and perform sensitive program operations.
|
CWE-352
Origin Validation Error
|
CVE-2020-19280
|
2024-11-21 14:09 |
2021-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211380
|
5.7 |
MEDIUM
Network
|
dswjcms_project
|
dswjcms
|
A cross-site request forgery (CSRF) in index.php/Dswjcms/User/tfAdd of Dswjcms 1.6.4 allows authenticated attackers to arbitrarily add administrator users.
|
CWE-352
Origin Validation Error
|
CVE-2020-19268
|
2024-11-21 14:09 |
2021-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|