CVE-2020-14017
- EPSS 0.39%
- Veröffentlicht 24.06.2020 15:15:12
- Zuletzt bearbeitet 21.11.2024 05:02:21
An issue was discovered in Navigate CMS 2.9 r1433. Sessions, as well as associated information such as CSRF tokens, are stored in cleartext files in the directory /private/sessions. An unauthenticated user could use a brute-force approach to attempt ...
CVE-2020-14015
- EPSS 0.25%
- Veröffentlicht 24.06.2020 15:15:11
- Zuletzt bearbeitet 21.11.2024 05:02:21
An issue was discovered in Navigate CMS 2.9 r1433. When performing a password reset, a user is emailed an activation code that allows them to reset their password. There is, however, a flaw when no activation code is supplied. The system will allow a...
CVE-2020-14014
- EPSS 0.21%
- Veröffentlicht 24.06.2020 15:15:11
- Zuletzt bearbeitet 21.11.2024 05:02:21
An issue was discovered in Navigate CMS 2.8 and 2.9 r1433. The query parameter fid on the resource navigate.php does not perform sufficient data validation and/or encoding, making it vulnerable to reflected XSS.
CVE-2020-14927
- EPSS 0.24%
- Veröffentlicht 19.06.2020 17:15:18
- Zuletzt bearbeitet 21.11.2024 05:04:27
Navigate CMS 2.9 allows XSS via the Alias or Real URL field of the "Web Sites > Create > Aliases > Add" screen.
CVE-2020-13798
- EPSS 0.24%
- Veröffentlicht 03.06.2020 22:15:11
- Zuletzt bearbeitet 21.11.2024 05:01:52
An issue was discovered in Navigate CMS through 2.8.7. It allows XSS because of a lack of purify calls in lib/packages/feeds/feed.class.php.
CVE-2020-13797
- EPSS 0.24%
- Veröffentlicht 03.06.2020 22:15:11
- Zuletzt bearbeitet 21.11.2024 05:01:52
An issue was discovered in Navigate CMS through 2.8.7. It allows XSS because of a lack of purify calls in lib/packages/websites/website.class.php.
CVE-2020-13796
- EPSS 0.24%
- Veröffentlicht 03.06.2020 22:15:11
- Zuletzt bearbeitet 21.11.2024 05:01:52
An issue was discovered in Navigate CMS through 2.8.7. It allows XSS because of a lack of purify calls in lib/packages/structure/structure.class.php.
CVE-2020-13795
- EPSS 0.32%
- Veröffentlicht 03.06.2020 22:15:11
- Zuletzt bearbeitet 21.11.2024 05:01:52
An issue was discovered in Navigate CMS through 2.8.7. It allows Directory Traversal because lib/packages/templates/template.class.php mishandles ../ and ..\ substrings.
CVE-2018-18029
- EPSS 0.19%
- Veröffentlicht 09.10.2018 17:29:01
- Zuletzt bearbeitet 21.11.2024 03:55:24
Navigate CMS has Stored XSS via the navigate.php Title field in an edit action.
CVE-2018-17849
- EPSS 0.21%
- Veröffentlicht 04.10.2018 21:29:01
- Zuletzt bearbeitet 21.11.2024 03:55:03
Navigate CMS 2.8 has Stored XSS via a navigate_upload.php (aka File Upload) request with a multipart/form-data JavaScript payload.