Facilemanager

Facilemanager

5 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.04%
  • Veröffentlicht 09.03.2026 22:54:49
  • Zuletzt bearbeitet 13.03.2026 14:51:44

facileManager is a modular suite of web apps built with the sysadmin in mind. Prior to 6.0.4 , stored XSS (also known as persistent or second-order XSS) occurs when an application receives data from an untrusted source and includes that data in its s...

Exploit
  • EPSS 0.04%
  • Veröffentlicht 09.03.2026 22:53:25
  • Zuletzt bearbeitet 13.03.2026 14:55:46

facileManager is a modular suite of web apps built with the sysadmin in mind. Prior to 6.0.4 , a reflected XSS occurs when an application receives data from an untrusted source and uses it in its HTTP responses in a way that could lead to vulnerabili...

Exploit
  • EPSS 0.36%
  • Veröffentlicht 31.01.2024 23:15:08
  • Zuletzt bearbeitet 21.11.2024 08:59:26

facileManager is a modular suite of web apps built with the sysadmin in mind. For the facileManager web application versions 4.5.0 and earlier, we have found that XSS was present in almost all of the input fields as there is insufficient input valida...

Exploit
  • EPSS 0.29%
  • Veröffentlicht 31.01.2024 23:15:08
  • Zuletzt bearbeitet 21.11.2024 08:59:26

facileManager is a modular suite of web apps built with the sysadmin in mind. In versions 4.5.0 and earlier, the $_REQUEST global array was unsafely called inside an extract() function in admin-logs.php. The PHP file fm-init.php prevents arbitrary ma...

Exploit
  • EPSS 0.54%
  • Veröffentlicht 31.01.2024 23:15:08
  • Zuletzt bearbeitet 21.11.2024 08:59:27

facileManager is a modular suite of web apps built with the sysadmin in mind. In versions 4.5.0 and earlier, when a user updates their profile, a POST request containing user information is sent to the endpoint server/fm-modules/facileManager/ajax/pr...