|
213041
|
4.3 |
MEDIUM
Network
|
qibosoft
|
qibosoft
|
A Cross-Site Request Forgery (CSRF) in /member/post.php?job=postnew&step=post of Qibosoft v7 allows attackers to force victim users into arbitrarily publishing new articles via a crafted URL.
|
CWE-352
Origin Validation Error
|
CVE-2020-20943
|
2024-11-21 14:12 |
2021-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213042
|
6.1 |
MEDIUM
Network
|
personal_blog_cms_project
|
personal_blog_cms
|
Blog CMS v1.0 contains a cross-site scripting (XSS) vulnerability in the /controller/CommentAdminController.java component.
|
CWE-79
Cross-site Scripting
|
CVE-2020-20605
|
2024-11-21 14:12 |
2021-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213043
|
9.8 |
CRITICAL
Network
|
thinkcmf
|
thinkcmf
|
An issue in ThinkCMF X2.2.2 and below allows attackers to execute arbitrary code via a crafted packet.
|
CWE-94
Code Injection
|
CVE-2020-20601
|
2024-11-21 14:12 |
2021-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213044
|
5.4 |
MEDIUM
Network
|
metinfo
|
metinfo
|
MetInfo 7.0 beta contains a stored cross-site scripting (XSS) vulnerability in the $name parameter of admin/?n=column&c=index&a=doAddColumn.
|
CWE-79
Cross-site Scripting
|
CVE-2020-20600
|
2024-11-21 14:12 |
2021-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213045
|
6.1 |
MEDIUM
Network
|
mossle
|
lemon
|
A cross-site scripting (XSS) vulnerability in the Editing component of lemon V1.10.0 allows attackers to execute arbitrary web scripts or HTML.
|
CWE-79
Cross-site Scripting
|
CVE-2020-20598
|
2024-11-21 14:12 |
2021-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213046
|
6.1 |
MEDIUM
Network
|
mossle
|
lemon
|
A cross-site scripting (XSS) vulnerability in the potrtalItemName parameter in \web\PortalController.java of lemon V1.10.0 allows attackers to execute arbitrary web scripts or HTML.
|
CWE-79
Cross-site Scripting
|
CVE-2020-20597
|
2024-11-21 14:12 |
2021-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213047
|
6.5 |
MEDIUM
Network
|
opms_project
|
opms
|
A cross-site request forgery (CSRF) in OPMS v1.3 and below allows attackers to arbitrarily add a user account via /user/add.
|
CWE-352
Origin Validation Error
|
CVE-2020-20595
|
2024-11-21 14:12 |
2021-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213048
|
8.0 |
HIGH
Network
|
rockoa
|
rockoa
|
A cross-site request forgery (CSRF) in Rockoa v1.9.8 allows an authenticated attacker to arbitrarily add an administrator account.
|
CWE-352
Origin Validation Error
|
CVE-2020-20593
|
2024-11-21 14:12 |
2021-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213049
|
6.1 |
MEDIUM
Network
|
s-cms
|
s-cms
|
S-CMS Government Station Building System v5.0 contains a cross-site scripting (XSS) vulnerability in /function/booksave.php.
|
CWE-79
Cross-site Scripting
|
CVE-2020-20426
|
2024-11-21 14:12 |
2021-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213050
|
6.1 |
MEDIUM
Network
|
s-cms
|
s-cms
|
S-CMS Government Station Building System v5.0 contains a cross-site scripting (XSS) vulnerability in the search function.
|
CWE-79
Cross-site Scripting
|
CVE-2020-20425
|
2024-11-21 14:12 |
2021-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|