Yzmcms

Yzmcms

49 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.59%
  • Veröffentlicht 23.09.2021 20:15:07
  • Zuletzt bearbeitet 21.11.2024 05:09:29

A cross-site scripting (XSS) vulnerability in the /link/add.html component of YzmCMS v5.3 allows attackers to execute arbitrary web scripts or HTML.

Exploit
  • EPSS 1.32%
  • Veröffentlicht 01.09.2021 20:15:07
  • Zuletzt bearbeitet 21.11.2024 05:12:01

YzmCMS v5.5 contains a server-side request forgery (SSRF) in the grab_image() function.

Exploit
  • EPSS 0.52%
  • Veröffentlicht 30.07.2021 14:15:13
  • Zuletzt bearbeitet 21.11.2024 05:08:57

Cross Site Scripting (XSS) vulnerabiity in YzmCMS 5.2 via the site_code parameter in admin/index/init.html.

Exploit
  • EPSS 0.5%
  • Veröffentlicht 03.06.2021 21:15:07
  • Zuletzt bearbeitet 21.11.2024 05:28:36

A storage XSS vulnerability is found in YzmCMS v5.8, which can be used by attackers to inject JS code and attack malicious XSS on the /admin/system_manage/user_config_edit.html page.

Exploit
  • EPSS 0.57%
  • Veröffentlicht 03.06.2021 21:15:07
  • Zuletzt bearbeitet 21.11.2024 05:28:36

An issue was discovered in YzmCMS V5.8. There is a CSRF vulnerability that can add member user accounts via member/member/add.html.

Exploit
  • EPSS 1.32%
  • Veröffentlicht 03.06.2021 21:15:07
  • Zuletzt bearbeitet 21.11.2024 05:28:36

An issue was discovered in YzmCMS 5.8. There is a SSRF vulnerability in the background collection management that allows arbitrary file read.

Exploit
  • EPSS 0.74%
  • Veröffentlicht 10.05.2021 23:15:07
  • Zuletzt bearbeitet 21.11.2024 05:13:47

In YzmCMS 5.6, stored XSS exists via the common/static/plugin/ueditor/1.4.3.3/php/controller.php action parameter, which allows remote attackers to upload a swf file. The swf file can be injected with arbitrary web script or HTML.

Exploit
  • EPSS 0.87%
  • Veröffentlicht 10.05.2021 23:15:07
  • Zuletzt bearbeitet 21.11.2024 05:13:47

In YzmCMS 5.6, XSS was discovered in member/member_content/init.html via the SRC attribute of an IFRAME element because of using UEditor 1.4.3.3.

Exploit
  • EPSS 1.32%
  • Veröffentlicht 30.04.2021 21:15:08
  • Zuletzt bearbeitet 21.11.2024 05:08:23

Cross Site Scripting (XSS) in yzmCMS v5.2 allows remote attackers to execute arbitrary code by injecting commands into the "referer" field of a POST request to the component "/member/index/login.html" when logging in.

Exploit
  • EPSS 0.73%
  • Veröffentlicht 19.11.2020 18:15:14
  • Zuletzt bearbeitet 21.11.2024 05:13:15

In YzmCMS v5.5 the member contribution function in the editor contains a cross-site scripting (XSS) vulnerability.