Vulnerabilities > Ofcms Project > Medium

DATE CVE VULNERABILITY TITLE RISK
2024-01-16 CVE-2023-51807 Cross-site Scripting vulnerability in Ofcms Project Ofcms 1.1.4
Cross Site Scripting vulnerability in OFCMS v.1.14 allows a remote attacker to obtain sensitive information via a crafted payload to the title addition component.
network
low complexity
ofcms-project CWE-79
5.4
2022-06-02 CVE-2022-29653 Cross-site Scripting vulnerability in Ofcms Project Ofcms 1.1.4
OFCMS v1.1.4 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /admin/comn/service/update.json.
4.3
2022-04-10 CVE-2022-27960 Incorrect Default Permissions vulnerability in Ofcms Project Ofcms 1.1.4
Insecure permissions configured in the user_id parameter at SysUserController.java of OFCMS v1.1.4 allows attackers to access and arbitrarily modify users' personal information.
network
low complexity
ofcms-project CWE-276
5.5
2019-03-06 CVE-2019-9617 Unrestricted Upload of File with Dangerous Type vulnerability in Ofcms Project Ofcms
An issue was discovered in OFCMS before 1.1.3.
network
low complexity
ofcms-project CWE-434
6.5
2019-03-06 CVE-2019-9616 Use of Incorrectly-Resolved Name or Reference vulnerability in Ofcms Project Ofcms
An issue was discovered in OFCMS before 1.1.3.
network
low complexity
ofcms-project CWE-706
6.5
2019-03-06 CVE-2019-9615 SQL Injection vulnerability in Ofcms Project Ofcms
An issue was discovered in OFCMS before 1.1.3.
network
low complexity
ofcms-project CWE-89
6.5
2019-03-06 CVE-2019-9614 Improper Input Validation vulnerability in Ofcms Project Ofcms
An issue was discovered in OFCMS before 1.1.3.
network
low complexity
ofcms-project CWE-20
6.5
2019-03-06 CVE-2019-9613 Unrestricted Upload of File with Dangerous Type vulnerability in Ofcms Project Ofcms
An issue was discovered in OFCMS before 1.1.3.
network
low complexity
ofcms-project CWE-434
6.5
2019-03-06 CVE-2019-9612 Unrestricted Upload of File with Dangerous Type vulnerability in Ofcms Project Ofcms
An issue was discovered in OFCMS before 1.1.3.
network
low complexity
ofcms-project CWE-434
6.5
2019-03-06 CVE-2019-9611 Path Traversal vulnerability in Ofcms Project Ofcms
An issue was discovered in OFCMS before 1.1.3.
network
low complexity
ofcms-project CWE-22
4.0