CVE-2020-19887
- EPSS 0.22%
- Veröffentlicht 24.08.2020 15:15:13
- Zuletzt bearbeitet 21.11.2024 05:09:27
DBHcms v1.2.0 has a stored XSS vulnerability as there is no htmlspecialchars function for '$_POST['pageparam_insert_description']' variable in dbhcms\mod\mod.page.edit.php line 227, A remote authenticated with admin user can exploit this vulnerabilit...
CVE-2020-19888
- EPSS 0.21%
- Veröffentlicht 24.08.2020 15:15:13
- Zuletzt bearbeitet 21.11.2024 05:09:27
DBHcms v1.2.0 has an unauthorized operation vulnerability because there's no access control at line 175 of dbhcms\page.php for empty cache operation. This vulnerability can be exploited to empty a table.
CVE-2020-19889
- EPSS 0.14%
- Veröffentlicht 24.08.2020 15:15:13
- Zuletzt bearbeitet 21.11.2024 05:09:28
DBHcms v1.2.0 has no CSRF protection mechanism,as demonstrated by CSRF for index.php?dbhcms_pid=-70 can add a user.
CVE-2020-19890
- EPSS 0.27%
- Veröffentlicht 24.08.2020 15:15:13
- Zuletzt bearbeitet 21.11.2024 05:09:28
DBHcms v1.2.0 has an Arbitrary file read vulnerability in dbhcms\mod\mod.editor.php $_GET['file'] is filename,and as there is no filter function for security, you can read any file's content.
CVE-2020-19877
- EPSS 0.63%
- Veröffentlicht 24.08.2020 14:15:12
- Zuletzt bearbeitet 21.11.2024 05:09:26
DBHcms v1.2.0 has a directory traversal vulnerability as there is no directory control function in directory /dbhcms/. A remote unauthenticated attacker can exploit this vulnerability to obtain server-sensitive information.