|
209131
|
5.4 |
MEDIUM
Network
|
jeesns
|
jeesns
|
A stored cross-site scripting (XSS) vulnerability in the /group/post component of Jeesns 1.4.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the title.
|
CWE-79
Cross-site Scripting
|
CVE-2020-19287
|
2024-11-21 14:09 |
2021-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209132
|
5.4 |
MEDIUM
Network
|
jeesns
|
jeesns
|
A stored cross-site scripting (XSS) vulnerability in the /question/detail component of Jeesns 1.4.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the source field…
|
CWE-79
Cross-site Scripting
|
CVE-2020-19286
|
2024-11-21 14:09 |
2021-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209133
|
5.4 |
MEDIUM
Network
|
jeesns
|
jeesns
|
A stored cross-site scripting (XSS) vulnerability in the /group/apply component of Jeesns 1.4.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the Name text field.
|
CWE-79
Cross-site Scripting
|
CVE-2020-19285
|
2024-11-21 14:09 |
2021-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209134
|
5.4 |
MEDIUM
Network
|
jeesns
|
jeesns
|
A stored cross-site scripting (XSS) vulnerability in the /group/comment component of Jeesns 1.4.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the group comments…
|
CWE-79
Cross-site Scripting
|
CVE-2020-19284
|
2024-11-21 14:09 |
2021-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209135
|
6.1 |
MEDIUM
Network
|
jeesns
|
jeesns
|
A reflected cross-site scripting (XSS) vulnerability in the /newVersion component of Jeesns 1.4.2 allows attackers to execute arbitrary web scripts or HTML.
|
CWE-79
Cross-site Scripting
|
CVE-2020-19283
|
2024-11-21 14:09 |
2021-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209136
|
6.1 |
MEDIUM
Network
|
jeesns
|
jeesns
|
A reflected cross-site scripting (XSS) vulnerability in Jeesns 1.4.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the system error message's text field.
|
CWE-79
Cross-site Scripting
|
CVE-2020-19282
|
2024-11-21 14:09 |
2021-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209137
|
5.4 |
MEDIUM
Network
|
jeesns
|
jeesns
|
A stored cross-site scripting (XSS) vulnerability in the /manage/loginusername component of Jeesns 1.4.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the usernam…
|
CWE-79
Cross-site Scripting
|
CVE-2020-19281
|
2024-11-21 14:09 |
2021-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209138
|
8.8 |
HIGH
Network
|
jeesns
|
jeesns
|
Jeesns 1.4.2 contains a cross-site request forgery (CSRF) which allows attackers to escalate privileges and perform sensitive program operations.
|
CWE-352
Origin Validation Error
|
CVE-2020-19280
|
2024-11-21 14:09 |
2021-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209139
|
5.7 |
MEDIUM
Network
|
dswjcms_project
|
dswjcms
|
A cross-site request forgery (CSRF) in index.php/Dswjcms/User/tfAdd of Dswjcms 1.6.4 allows authenticated attackers to arbitrarily add administrator users.
|
CWE-352
Origin Validation Error
|
CVE-2020-19268
|
2024-11-21 14:09 |
2021-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209140
|
9.8 |
CRITICAL
Network
|
dswjcms_project
|
dswjcms
|
An issue in index.php/Dswjcms/Basis/resources of Dswjcms 1.6.4 allows attackers to execute arbitrary code via uploading a crafted PHP file.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-19267
|
2024-11-21 14:09 |
2021-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|