Magnolia-cms

Magnolia Cms

9 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.84%
  • Veröffentlicht 07.07.2022 19:15:08
  • Zuletzt bearbeitet 21.11.2024 07:07:32

Magnolia CMS v6.2.19 was discovered to contain a cross-site scripting (XSS) vulnerability via the Edit Contact function. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

Exploit
  • EPSS 1%
  • Veröffentlicht 11.02.2022 21:15:11
  • Zuletzt bearbeitet 21.11.2024 06:33:58

An issue in the Freemark Filter of Magnolia CMS v6.2.11 and below allows attackers to bypass security restrictions and execute arbitrary code via a crafted FreeMarker payload.

Exploit
  • EPSS 1.78%
  • Veröffentlicht 11.02.2022 21:15:11
  • Zuletzt bearbeitet 21.11.2024 06:33:58

A Server-Side Template Injection (SSTI) vulnerability in the Registration and Forgotten Password forms of Magnolia v6.2.3 and below allows attackers to execute arbitrary code via a crafted payload entered into the fullname parameter.

Exploit
  • EPSS 1.23%
  • Veröffentlicht 11.02.2022 21:15:11
  • Zuletzt bearbeitet 21.11.2024 06:33:58

An issue in the Export function of Magnolia v6.2.3 and below allows attackers to perform Formula Injection attacks via crafted CSV/XLS files. These formulas may result in arbitrary code execution on a victim's computer when opening the exported files...

Exploit
  • EPSS 1%
  • Veröffentlicht 11.02.2022 21:15:11
  • Zuletzt bearbeitet 21.11.2024 06:33:58

A vulnerability in the Snake YAML parser of Magnolia CMS v6.2.3 and below allows attackers to execute arbitrary code via a crafted YAML file.

Exploit
  • EPSS 0.51%
  • Veröffentlicht 11.02.2022 21:15:11
  • Zuletzt bearbeitet 21.11.2024 06:33:58

An issue in the Export function of Magnolia v6.2.3 and below allows attackers to execute XML External Entity attacks via a crafted XLF file.

Exploit
  • EPSS 0.53%
  • Veröffentlicht 11.02.2022 21:15:11
  • Zuletzt bearbeitet 21.11.2024 06:33:58

An issue in the Login page of Magnolia CMS v6.2.3 and below allows attackers to exploit both an Open Redirect vulnerability and Cross-Site Request Forgery (CSRF) in order to brute force and exfiltrate users' credentials.

Exploit
  • EPSS 0.38%
  • Veröffentlicht 02.04.2021 12:15:33
  • Zuletzt bearbeitet 21.11.2024 05:55:33

Magnolia CMS from 6.1.3 to 6.2.3 contains a stored cross-site scripting (XSS) vulnerability in the setText parameter of /magnoliaAuthor/.magnolia/.

Exploit
  • EPSS 0.4%
  • Veröffentlicht 02.04.2021 12:15:33
  • Zuletzt bearbeitet 21.11.2024 05:55:33

Magnolia CMS from 6.1.3 to 6.2.3 contains a stored cross-site scripting (XSS) vulnerability in the /magnoliaPublic/travel/members/login.html mgnlUserId parameter.