Vulnerabilities > Joruri

DATE CVE VULNERABILITY TITLE RISK
2019-07-05 CVE-2019-5967 Cross-site Scripting vulnerability in Joruri CMS 2017 Release0/Release1/Release2
Cross-site scripting vulnerability in Joruri CMS 2017 Release2 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
network
low complexity
joruri CWE-79
6.1
2019-07-05 CVE-2019-5966 Authorization Bypass Through User-Controlled Key vulnerability in Joruri Mail 2.1.4
Joruri Mail 2.1.4 and earlier does not properly manage sessions, which allows remote attackers to impersonate an arbitrary user and alter/disclose the information via unspecified vectors.
network
low complexity
joruri CWE-639
5.4
2019-07-05 CVE-2019-5965 Open Redirect vulnerability in Joruri Mail 2.1.4
Open redirect vulnerability in Joruri Mail 2.1.4 and earlier allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
network
low complexity
joruri CWE-601
6.1