Vulnerabilities > Getsymphony

DATE CVE VULNERABILITY TITLE RISK
2016-01-08 CVE-2015-8766 Cross-site Scripting vulnerability in Getsymphony Symphony
Multiple cross-site scripting (XSS) vulnerabilities in content/content.systempreferences.php in Symphony CMS before 2.6.4 allow remote attackers to inject arbitrary web script or HTML via the (1) email_sendmail[from_name], (2) email_sendmail[from_address], (3) email_smtp[from_name], (4) email_smtp[from_address], (5) email_smtp[host], (6) email_smtp[port], (7) jit_image_manipulation[trusted_external_sites], or (8) maintenance_mode[ip_whitelist] parameters to system/preferences.
network
low complexity
getsymphony CWE-79
6.1
2016-01-08 CVE-2015-8376 Cross-site Scripting vulnerability in Getsymphony Symphony 2.6.3
Multiple cross-site scripting (XSS) vulnerabilities in Symphony CMS 2.6.3 allow remote attackers to inject arbitrary web script or HTML via the (1) Name, (2) Navigation Group, or (3) Label parameter to blueprints/sections/edit/1.
network
low complexity
getsymphony CWE-79
6.1