CVE-2020-21333
- EPSS 0.26%
- Veröffentlicht 09.07.2021 17:15:07
- Zuletzt bearbeitet 21.11.2024 05:12:31
Cross Site Scripting (XSS) vulnerability in PublicCMS 4.0 to get an admin cookie when the Administrator reviews submit case.
CVE-2018-18927
- EPSS 0.24%
- Veröffentlicht 04.11.2018 05:29:00
- Zuletzt bearbeitet 21.11.2024 03:56:53
An issue was discovered in PublicCMS V4.0. It allows XSS by modifying the page_list "attached" attribute (which typically has 'class="icon-globe icon-large"' in its value), as demonstrated by an 'UPDATE sys_module SET attached = "[XSS]" WHERE id="pag...
CVE-2018-17368
- EPSS 0.23%
- Veröffentlicht 23.09.2018 22:29:00
- Zuletzt bearbeitet 21.11.2024 03:54:16
An issue was discovered in PublicCMS V4.0.180825. For an invalid login attempt, the response length is different depending on whether the username is valid, which makes it easier to conduct brute-force attacks.
CVE-2018-12914
- EPSS 2.37%
- Veröffentlicht 27.06.2018 18:29:00
- Zuletzt bearbeitet 21.11.2024 03:46:05
A remote code execution issue was discovered in PublicCMS V4.0.20180210. An attacker can upload a ZIP archive that contains a .jsp file with a directory traversal pathname. After an unzip operation, the attacker can execute arbitrary code by visiting...
CVE-2018-12494
- EPSS 0.52%
- Veröffentlicht 15.06.2018 18:29:00
- Zuletzt bearbeitet 21.11.2024 03:45:19
An issue was discovered in PublicCMS V4.0.20180210. There is a "Directory Traversal" and "Arbitrary file read" vulnerability via an admin/cmsTemplate/content.html?path=../ URI.
CVE-2018-12493
- EPSS 0.54%
- Veröffentlicht 15.06.2018 18:29:00
- Zuletzt bearbeitet 21.11.2024 03:45:19
An issue was discovered in PublicCMS V4.0.20180210. There is a "Directory Traversal" and "Arbitrary file read" vulnerability via an admin/cmsWebFile/list.html?path=../ URI.
CVE-2018-11500
- EPSS 0.16%
- Veröffentlicht 26.05.2018 21:29:00
- Zuletzt bearbeitet 21.11.2024 03:43:29
An issue was discovered in PublicCMS V4.0.20180210. There is a CSRF vulnerability in "admin/sysUser/save.do?callbackType=closeCurrent&navTabId=sysUser/list" that can add an admin account.