Vulnerabilities > Bycms Project

DATE CVE VULNERABILITY TITLE RISK
2021-08-12 CVE-2020-18454 Cross-Site Request Forgery (CSRF) vulnerability in Bycms Project Bycms 1.3.0
Cross Site Request Forgery (CSRF) vulnerability in bycms v1.3 via admin.php/systems/index/module_id/70/group_id/1.html.
network
low complexity
bycms-project CWE-352
6.8
2021-08-12 CVE-2020-18455 Cross-site Scripting vulnerability in Bycms Project Bycms 1.3.0
Cross Site Scripting (XSS) vulnerability exists in bycms v3.0.4 via the title parameter in the edit function in Document.php.
network
low complexity
bycms-project CWE-79
4.8
2021-08-12 CVE-2020-18457 Cross-Site Request Forgery (CSRF) vulnerability in Bycms Project Bycms 1.3.0
Cross Site Request Forgery (CSRF) vulnerability exists in bycms v1.3.0 that can add an admin account via admin.php/ucenter/add.html.
network
low complexity
bycms-project CWE-352
6.8