Vulnerabilities > Xiao5Ucompany Project

DATE CVE VULNERABILITY TITLE RISK
2018-08-06 CVE-2018-14960 Cross-Site Request Forgery (CSRF) vulnerability in Xiao5Ucompany Project Xiao5Ucompany 1.7
Xiao5uCompany 1.7 has CSRF via admin/Admin.asp.
network
low complexity
xiao5ucompany-project CWE-352
8.8
2018-07-23 CVE-2018-14527 Cross-site Scripting vulnerability in Xiao5Ucompany Project Xiao5Ucompany 1.7
Feedback.asp in Xiao5uCompany 1.7 has XSS because the XSS protection mechanism in Safe.asp is insufficient (for example, it considers SCRIPT and IMG elements, but does not consider VIDEO elements).
network
low complexity
xiao5ucompany-project CWE-79
6.1