Vulnerabilities > Dbhcms Project > Dbhcms > Low

DATE CVE VULNERABILITY TITLE RISK
2020-08-24 CVE-2020-19881 Cross-site Scripting vulnerability in Dbhcms Project Dbhcms 1.2.0
DBHcms v1.2.0 has a reflected xss vulnerability as there is no security filter in dbhcms\mod\mod.selector.php line 108 for $_GET['return_name'] parameter, A remote authenticated with admin user can exploit this vulnerability to hijack other users.
3.5
2020-08-24 CVE-2020-19882 Cross-site Scripting vulnerability in Dbhcms Project Dbhcms 1.2.0
DBHcms v1.2.0 has a stored xss vulnerability as there is no htmlspecialchars function for 'menu_description' variable in dbhcms\mod\mod.menus.edit.php line 83 and in dbhcms\mod\mod.menus.view.php line 111, A remote authenticated with admin user can exploit this vulnerability to hijack other users.
3.5
2020-08-24 CVE-2020-19883 Cross-site Scripting vulnerability in Dbhcms Project Dbhcms 1.2.0
DBHcms v1.2.0 has a stored xss vulnerability as there is no security filter in dbhcms\mod\mod.users.view.php line 57 for user_login, A remote authenticated with admin user can exploit this vulnerability to hijack other users.
3.5
2020-08-24 CVE-2020-19884 Cross-site Scripting vulnerability in Dbhcms Project Dbhcms 1.2.0
DBHcms v1.2.0 has a stored xss vulnerability as there is no htmlspecialchars function in dbhcms\mod\mod.domain.edit.php line 119.
3.5
2020-08-24 CVE-2020-19885 Cross-site Scripting vulnerability in Dbhcms Project Dbhcms 1.2.0
DBHcms v1.2.0 has a stored xss vulnerability as there is no htmlspecialchars function for '$_POST['pageparam_insert_name']' variable in dbhcms\mod\mod.page.edit.php line 227, A remote authenticated with admin user can exploit this vulnerability to hijack other users.
3.5
2020-08-24 CVE-2020-19887 Cross-site Scripting vulnerability in Dbhcms Project Dbhcms 1.2.0
DBHcms v1.2.0 has a stored XSS vulnerability as there is no htmlspecialchars function for '$_POST['pageparam_insert_description']' variable in dbhcms\mod\mod.page.edit.php line 227, A remote authenticated with admin user can exploit this vulnerability to hijack other users.
3.5