|
209711
|
5.4 |
MEDIUM
Network
|
catalyst
|
mahara
|
Catalyst IT Ltd Mahara CMS v19.10.2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component groupfiles.php via the Number (Nombre) and Description (Descripción)…
|
CWE-79
Cross-site Scripting
|
CVE-2020-23052
|
2024-11-21 14:13 |
2021-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209712
|
6.1 |
MEDIUM
Network
|
user_registration_\&_login_and_user_management_system_with_admin_panel_project
|
user_registration_\&_login_and_user_management_system_with_admin_panel
|
Phpgurukul User Registration & User Management System v2.0 was discovered to contain multiple stored cross-site scripting (XSS) vulnerabilities via the firstname and lastname parameters of the regist…
|
CWE-79
Cross-site Scripting
|
CVE-2020-23051
|
2024-11-21 14:13 |
2021-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209713
|
8.0 |
HIGH
Network
|
taotesting
|
tao_assessment_platform
|
TAO Open Source Assessment Platform v3.3.0 RC02 was discovered to contain a HTML injection vulnerability in the userFirstName parameter of the user account input field. This vulnerability allows atta…
|
CWE-74
Injection
|
CVE-2020-23050
|
2024-11-21 14:13 |
2021-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209714
|
5.4 |
MEDIUM
Network
|
fork-cms
|
fork_cms
|
Fork CMS Content Management System v5.8.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the `Displayname` field when using the `Add`, `Edit` or `Register' functions. This vu…
|
CWE-79
Cross-site Scripting
|
CVE-2020-23049
|
2024-11-21 14:13 |
2021-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209715
|
6.1 |
MEDIUM
Network
|
seeddms
|
seeddms
|
SeedDMS Content Management System v6.0.7 contains a persistent cross-site scripting (XSS) vulnerability in the component AddEvent.php via the name and comment parameters.
|
CWE-79
Cross-site Scripting
|
CVE-2020-23048
|
2024-11-21 14:13 |
2021-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209716
|
6.1 |
MEDIUM
Network
|
macs_cms_project
|
macs_cms
|
Macrob7 Macs Framework Content Management System - 1.14f was discovered to contain a cross-site scripting (XSS) vulnerability in the search input field of the search module.
|
CWE-79
Cross-site Scripting
|
CVE-2020-23047
|
2024-11-21 14:13 |
2021-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209717
|
6.1 |
MEDIUM
Network
|
dedecms
|
dedecms
|
DedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component tpl.php via the `filename`, `mid`, `userid`, and `templet' parameters.
|
CWE-79
Cross-site Scripting
|
CVE-2020-23046
|
2024-11-21 14:13 |
2021-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209718
|
7.2 |
HIGH
Network
|
macs_cms_project
|
macs_cms
|
Macrob7 Macs Framework Content Management System - 1.14f was discovered to contain a SQL injection vulnerability via the 'roleId' parameter of the `editRole` and `deletUser` modules.
|
CWE-89
SQL Injection
|
CVE-2020-23045
|
2024-11-21 14:13 |
2021-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209719
|
5.4 |
MEDIUM
Network
|
dedecms
|
dedecms
|
DedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component file_pic_view.php via the `activepath`, `keyword`, `tag`, `fmdo=x&filename`, `CKEditor`…
|
CWE-79
Cross-site Scripting
|
CVE-2020-23044
|
2024-11-21 14:13 |
2021-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209720
|
8.8 |
HIGH
Network
|
air_sender_project
|
air_sender
|
Tran Tu Air Sender v1.0.2 was discovered to contain an arbitrary file upload vulnerability in the upload module. This vulnerability allows attackers to execute arbitrary code via a crafted file.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-23043
|
2024-11-21 14:13 |
2021-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|