Naviwebs

Navigate Cms

22 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.39%
  • Veröffentlicht 24.06.2020 15:15:12
  • Zuletzt bearbeitet 21.11.2024 05:02:21

An issue was discovered in Navigate CMS 2.9 r1433. Sessions, as well as associated information such as CSRF tokens, are stored in cleartext files in the directory /private/sessions. An unauthenticated user could use a brute-force approach to attempt ...

Exploit
  • EPSS 0.25%
  • Veröffentlicht 24.06.2020 15:15:11
  • Zuletzt bearbeitet 21.11.2024 05:02:21

An issue was discovered in Navigate CMS 2.9 r1433. When performing a password reset, a user is emailed an activation code that allows them to reset their password. There is, however, a flaw when no activation code is supplied. The system will allow a...

Exploit
  • EPSS 0.21%
  • Veröffentlicht 24.06.2020 15:15:11
  • Zuletzt bearbeitet 21.11.2024 05:02:21

An issue was discovered in Navigate CMS 2.8 and 2.9 r1433. The query parameter fid on the resource navigate.php does not perform sufficient data validation and/or encoding, making it vulnerable to reflected XSS.

Exploit
  • EPSS 0.24%
  • Veröffentlicht 19.06.2020 17:15:18
  • Zuletzt bearbeitet 21.11.2024 05:04:27

Navigate CMS 2.9 allows XSS via the Alias or Real URL field of the "Web Sites > Create > Aliases > Add" screen.

  • EPSS 0.24%
  • Veröffentlicht 03.06.2020 22:15:11
  • Zuletzt bearbeitet 21.11.2024 05:01:52

An issue was discovered in Navigate CMS through 2.8.7. It allows XSS because of a lack of purify calls in lib/packages/feeds/feed.class.php.

  • EPSS 0.24%
  • Veröffentlicht 03.06.2020 22:15:11
  • Zuletzt bearbeitet 21.11.2024 05:01:52

An issue was discovered in Navigate CMS through 2.8.7. It allows XSS because of a lack of purify calls in lib/packages/websites/website.class.php.

  • EPSS 0.24%
  • Veröffentlicht 03.06.2020 22:15:11
  • Zuletzt bearbeitet 21.11.2024 05:01:52

An issue was discovered in Navigate CMS through 2.8.7. It allows XSS because of a lack of purify calls in lib/packages/structure/structure.class.php.

  • EPSS 0.32%
  • Veröffentlicht 03.06.2020 22:15:11
  • Zuletzt bearbeitet 21.11.2024 05:01:52

An issue was discovered in Navigate CMS through 2.8.7. It allows Directory Traversal because lib/packages/templates/template.class.php mishandles ../ and ..\ substrings.

Exploit
  • EPSS 0.19%
  • Veröffentlicht 09.10.2018 17:29:01
  • Zuletzt bearbeitet 21.11.2024 03:55:24

Navigate CMS has Stored XSS via the navigate.php Title field in an edit action.

Exploit
  • EPSS 0.21%
  • Veröffentlicht 04.10.2018 21:29:01
  • Zuletzt bearbeitet 21.11.2024 03:55:03

Navigate CMS 2.8 has Stored XSS via a navigate_upload.php (aka File Upload) request with a multipart/form-data JavaScript payload.