|
208661
|
6.5 |
MEDIUM
Network
|
maccms
|
maccms
|
A cross-site request forgery (CSRF) in Maccms 8.0 causes administrators to add and modify articles without their knowledge via clicking on a crafted URL.
|
CWE-352
Origin Validation Error
|
CVE-2020-21081
|
2024-11-21 14:12 |
2021-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208662
|
7.8 |
HIGH
Local
|
kitesky
|
kitecms
|
An arbitrary file upload vulnerability in /admin/upload/uploadfile of KiteCMS V1.1 allows attackers to getshell via a crafted PHP file.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-20672
|
2024-11-21 14:12 |
2021-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208663
|
8.8 |
HIGH
Network
|
kitesky
|
kitecms
|
A cross-site request forgery (CSRF) in KiteCMS V1.1 allows attackers to arbitrarily add an administrator account.
|
CWE-352
Origin Validation Error
|
CVE-2020-20671
|
2024-11-21 14:12 |
2021-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208664
|
8.8 |
HIGH
Network
|
zkea
|
zkeacms
|
An arbitrary file upload vulnerability in /admin/media/upload of ZKEACMS V3.2.0 allows attackers to execute arbitrary code via a crafted HTML file.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-20670
|
2024-11-21 14:12 |
2021-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208665
|
5.4 |
MEDIUM
Network
|
wtcms_project
|
wtcms
|
WTCMS 1.0 contains a stored cross-site scripting (XSS) vulnerability in the link address field under the background links module.
|
CWE-79
Cross-site Scripting
|
CVE-2020-20349
|
2024-11-21 14:12 |
2021-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208666
|
5.4 |
MEDIUM
Network
|
wtcms_project
|
wtcms
|
WTCMS 1.0 contains a stored cross-site scripting (XSS) vulnerability in the link field under the background menu management module.
|
CWE-79
Cross-site Scripting
|
CVE-2020-20348
|
2024-11-21 14:12 |
2021-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208667
|
5.4 |
MEDIUM
Network
|
wtcms_project
|
wtcms
|
WTCMS 1.0 contains a stored cross-site scripting (XSS) vulnerability in the source field under the article management module.
|
CWE-79
Cross-site Scripting
|
CVE-2020-20347
|
2024-11-21 14:12 |
2021-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208668
|
5.4 |
MEDIUM
Network
|
wtcms_project
|
wtcms
|
WTCMS 1.0 contains a reflective cross-site scripting (XSS) vulnerability in the page management background which allows attackers to obtain cookies via a crafted payload entered into the search box.
|
CWE-79
Cross-site Scripting
|
CVE-2020-20345
|
2024-11-21 14:12 |
2021-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208669
|
5.4 |
MEDIUM
Network
|
wtcms_project
|
wtcms
|
WTCMS 1.0 contains a reflective cross-site scripting (XSS) vulnerability in the keyword search function under the background articles module.
|
CWE-79
Cross-site Scripting
|
CVE-2020-20344
|
2024-11-21 14:12 |
2021-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208670
|
6.5 |
MEDIUM
Network
|
wtcms_project
|
wtcms
|
WTCMS 1.0 contains a cross-site request forgery (CSRF) vulnerability in the index.php?g=admin&m=nav&a=add_post component that allows attackers to arbitrarily add articles in the administrator backgro…
|
CWE-352
Origin Validation Error
|
CVE-2020-20343
|
2024-11-21 14:12 |
2021-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|