|
210781
|
6.1 |
MEDIUM
Network
|
mossle
|
lemon
|
A cross-site scripting (XSS) vulnerability in the Editing component of lemon V1.10.0 allows attackers to execute arbitrary web scripts or HTML.
|
CWE-79
Cross-site Scripting
|
CVE-2020-20598
|
2024-11-21 14:12 |
2021-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210782
|
6.1 |
MEDIUM
Network
|
mossle
|
lemon
|
A cross-site scripting (XSS) vulnerability in the potrtalItemName parameter in \web\PortalController.java of lemon V1.10.0 allows attackers to execute arbitrary web scripts or HTML.
|
CWE-79
Cross-site Scripting
|
CVE-2020-20597
|
2024-11-21 14:12 |
2021-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210783
|
6.5 |
MEDIUM
Network
|
opms_project
|
opms
|
A cross-site request forgery (CSRF) in OPMS v1.3 and below allows attackers to arbitrarily add a user account via /user/add.
|
CWE-352
Origin Validation Error
|
CVE-2020-20595
|
2024-11-21 14:12 |
2021-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210784
|
8.0 |
HIGH
Network
|
rockoa
|
rockoa
|
A cross-site request forgery (CSRF) in Rockoa v1.9.8 allows an authenticated attacker to arbitrarily add an administrator account.
|
CWE-352
Origin Validation Error
|
CVE-2020-20593
|
2024-11-21 14:12 |
2021-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210785
|
6.1 |
MEDIUM
Network
|
s-cms
|
s-cms
|
S-CMS Government Station Building System v5.0 contains a cross-site scripting (XSS) vulnerability in /function/booksave.php.
|
CWE-79
Cross-site Scripting
|
CVE-2020-20426
|
2024-11-21 14:12 |
2021-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210786
|
6.1 |
MEDIUM
Network
|
s-cms
|
s-cms
|
S-CMS Government Station Building System v5.0 contains a cross-site scripting (XSS) vulnerability in the search function.
|
CWE-79
Cross-site Scripting
|
CVE-2020-20425
|
2024-11-21 14:12 |
2021-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210787
|
6.1 |
MEDIUM
Network
|
ruijie
|
rg-uac_6000-e50_firmware
|
Ruijie RG-UAC 6000-E50 commit 9071227 was discovered to contain a cross-site scripting (XSS) vulnerability via the rule_name parameter. This vulnerability allows attackers to execute arbitrary web sc…
|
CWE-79
Cross-site Scripting
|
CVE-2020-21639
|
2024-11-21 14:12 |
2021-11-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210788
|
7.5 |
HIGH
Network
|
ruijie
|
rg-uac_firmware
|
Ruijie RG-UAC commit 9071227 was discovered to contain a vulnerability in the component /current_action.php?action=reboot, which allows attackers to cause a denial of service (DoS) via unspecified ve…
|
NVD-CWE-noinfo
|
CVE-2020-21627
|
2024-11-21 14:12 |
2021-11-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210789
|
8.8 |
HIGH
Network
|
idreamsoft
|
icms
|
iCMS v7.0.15 was discovered to contain a Cross-Site Request Forgery (CSRF) via /admincp.php?app=members&do=add.
|
CWE-352
Origin Validation Error
|
CVE-2020-21141
|
2024-11-21 14:12 |
2021-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210790
|
6.5 |
MEDIUM
Network
|
ec_cloud_e-commerce_system_project
|
ec_cloud_e-commerce_system
|
EC Cloud E-Commerce System v1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) which allows attackers to arbitrarily add admin accounts via /admin.html?do=user&act=add.
|
CWE-352
Origin Validation Error
|
CVE-2020-21139
|
2024-11-21 14:12 |
2021-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|