Vulnerabilities > Dswjcms Project
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2021-09-09 | CVE-2020-19265 | Cross-site Scripting vulnerability in Dswjcms Project Dswjcms 1.6.4 A stored cross-site scripting (XSS) vulnerability in the index.php/Dswjcms/Basis/links component of Dswjcms 1.6.4 allows attackers to execute arbitrary web scripts or HTML. | 6.1 |
2021-09-09 | CVE-2020-19266 | Cross-site Scripting vulnerability in Dswjcms Project Dswjcms 1.6.4 A stored cross-site scripting (XSS) vulnerability in the index.php/Dswjcms/Site/articleList component of Dswjcms 1.6.4 allows attackers to execute arbitrary web scripts or HTML. | 6.1 |
2021-09-09 | CVE-2020-19267 | Unrestricted Upload of File with Dangerous Type vulnerability in Dswjcms Project Dswjcms 1.6.4 An issue in index.php/Dswjcms/Basis/resources of Dswjcms 1.6.4 allows attackers to execute arbitrary code via uploading a crafted PHP file. | 9.8 |
2021-09-09 | CVE-2020-19268 | Cross-Site Request Forgery (CSRF) vulnerability in Dswjcms Project Dswjcms 1.6.4 A cross-site request forgery (CSRF) in index.php/Dswjcms/User/tfAdd of Dswjcms 1.6.4 allows authenticated attackers to arbitrarily add administrator users. | 5.7 |