The WEB control panel before 2019-04-30 for ClonOS allows SQL injection in clonos.php.
9.8CVSS
9.8AI Score
0.001EPSS
clonos.php in ClonOS WEB control panel 19.09 allows remote attackers to gain full access via change password requests because there is no session management.
9.8CVSS
9.6AI Score
0.095EPSS
A cross-site scripting (XSS) vulnerability in index.php in ClonOS WEB control panel 19.09 allows remote attackers to inject arbitrary web script or HTML via the lang parameter.
6.1CVSS
5.9AI Score
0.001EPSS