Lucene search

K

Dswjcms Project Security Vulnerabilities

cve
cve

CVE-2020-19265

A stored cross-site scripting (XSS) vulnerability in the index.php/Dswjcms/Basis/links component of Dswjcms 1.6.4 allows attackers to execute arbitrary web scripts or HTML.

6.1CVSS

5.9AI Score

0.001EPSS

2021-09-09 06:15 PM
20
cve
cve

CVE-2020-19266

A stored cross-site scripting (XSS) vulnerability in the index.php/Dswjcms/Site/articleList component of Dswjcms 1.6.4 allows attackers to execute arbitrary web scripts or HTML.

6.1CVSS

5.9AI Score

0.001EPSS

2021-09-09 06:15 PM
19
cve
cve

CVE-2020-19267

An issue in index.php/Dswjcms/Basis/resources of Dswjcms 1.6.4 allows attackers to execute arbitrary code via uploading a crafted PHP file.

9.8CVSS

9.5AI Score

0.005EPSS

2021-09-09 06:15 PM
23
cve
cve

CVE-2020-19268

A cross-site request forgery (CSRF) in index.php/Dswjcms/User/tfAdd of Dswjcms 1.6.4 allows authenticated attackers to arbitrarily add administrator users.

5.7CVSS

5.5AI Score

0.001EPSS

2021-09-09 06:15 PM
18