CVE-2020-19287
- EPSS 0.17%
- Veröffentlicht 09.09.2021 23:15:09
- Zuletzt bearbeitet 21.11.2024 05:09:06
A stored cross-site scripting (XSS) vulnerability in the /group/post component of Jeesns 1.4.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the title.
CVE-2020-19285
- EPSS 0.26%
- Veröffentlicht 09.09.2021 23:15:09
- Zuletzt bearbeitet 21.11.2024 05:09:05
A stored cross-site scripting (XSS) vulnerability in the /group/apply component of Jeesns 1.4.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the Name text field.
CVE-2020-19284
- EPSS 0.19%
- Veröffentlicht 09.09.2021 23:15:09
- Zuletzt bearbeitet 21.11.2024 05:09:05
A stored cross-site scripting (XSS) vulnerability in the /group/comment component of Jeesns 1.4.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the group comments text field.
CVE-2020-19283
- EPSS 2.55%
- Veröffentlicht 09.09.2021 23:15:09
- Zuletzt bearbeitet 21.11.2024 05:09:05
A reflected cross-site scripting (XSS) vulnerability in the /newVersion component of Jeesns 1.4.2 allows attackers to execute arbitrary web scripts or HTML.
CVE-2020-19282
- EPSS 6.61%
- Veröffentlicht 09.09.2021 23:15:09
- Zuletzt bearbeitet 21.11.2024 05:09:05
A reflected cross-site scripting (XSS) vulnerability in Jeesns 1.4.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the system error message's text field.
CVE-2020-19281
- EPSS 0.26%
- Veröffentlicht 09.09.2021 23:15:09
- Zuletzt bearbeitet 21.11.2024 05:09:05
A stored cross-site scripting (XSS) vulnerability in the /manage/loginusername component of Jeesns 1.4.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the username field.
CVE-2020-19280
- EPSS 0.88%
- Veröffentlicht 09.09.2021 23:15:07
- Zuletzt bearbeitet 21.11.2024 05:09:05
Jeesns 1.4.2 contains a cross-site request forgery (CSRF) which allows attackers to escalate privileges and perform sensitive program operations.
CVE-2020-18035
- EPSS 0.43%
- Veröffentlicht 29.04.2021 23:15:07
- Zuletzt bearbeitet 21.11.2024 05:08:22
Cross Site Scripting (XSS) in Jeesns v1.4.2 allows remote attackers to execute arbitrary code by injecting commands into the "CKEditorFuncNum" parameter in the component "CkeditorUploadController.java".
CVE-2018-19178
- EPSS 0.28%
- Veröffentlicht 11.11.2018 16:29:00
- Zuletzt bearbeitet 21.11.2024 03:57:28
In JEESNS 1.3, com/lxinet/jeesns/core/utils/XssHttpServletRequestWrapper.java allows stored XSS via an HTML EMBED element, a different vulnerability than CVE-2018-17886.
CVE-2018-17886
- EPSS 0.21%
- Veröffentlicht 02.10.2018 18:29:02
- Zuletzt bearbeitet 21.11.2024 03:55:08
An issue was discovered in JEESNS 1.3. The XSS filter in com.lxinet.jeesns.core.utils.XssHttpServletRequestWrapper.java could be bypassed, as demonstrated by a <svg/onLoad=confirm substring. NOTE: this vulnerability exists because of an incomplete fi...