CVE-2020-19287
- EPSS 0.64%
- Veröffentlicht 09.09.2021 23:15:09
- Zuletzt bearbeitet 21.11.2024 05:09:06
A stored cross-site scripting (XSS) vulnerability in the /group/post component of Jeesns 1.4.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the title.
CVE-2020-19285
- EPSS 0.64%
- Veröffentlicht 09.09.2021 23:15:09
- Zuletzt bearbeitet 21.11.2024 05:09:05
A stored cross-site scripting (XSS) vulnerability in the /group/apply component of Jeesns 1.4.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the Name text field.
CVE-2020-19284
- EPSS 0.53%
- Veröffentlicht 09.09.2021 23:15:09
- Zuletzt bearbeitet 21.11.2024 05:09:05
A stored cross-site scripting (XSS) vulnerability in the /group/comment component of Jeesns 1.4.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the group comments text field.
CVE-2020-19283
- EPSS 3%
- Veröffentlicht 09.09.2021 23:15:09
- Zuletzt bearbeitet 21.11.2024 05:09:05
A reflected cross-site scripting (XSS) vulnerability in the /newVersion component of Jeesns 1.4.2 allows attackers to execute arbitrary web scripts or HTML.
CVE-2020-19282
- EPSS 2.99%
- Veröffentlicht 09.09.2021 23:15:09
- Zuletzt bearbeitet 21.11.2024 05:09:05
A reflected cross-site scripting (XSS) vulnerability in Jeesns 1.4.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the system error message's text field.
CVE-2020-19281
- EPSS 0.54%
- Veröffentlicht 09.09.2021 23:15:09
- Zuletzt bearbeitet 21.11.2024 05:09:05
A stored cross-site scripting (XSS) vulnerability in the /manage/loginusername component of Jeesns 1.4.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the username field.
CVE-2020-19280
- EPSS 0.85%
- Veröffentlicht 09.09.2021 23:15:07
- Zuletzt bearbeitet 21.11.2024 05:09:05
Jeesns 1.4.2 contains a cross-site request forgery (CSRF) which allows attackers to escalate privileges and perform sensitive program operations.
CVE-2020-18035
- EPSS 1.03%
- Veröffentlicht 29.04.2021 23:15:07
- Zuletzt bearbeitet 21.11.2024 05:08:22
Cross Site Scripting (XSS) in Jeesns v1.4.2 allows remote attackers to execute arbitrary code by injecting commands into the "CKEditorFuncNum" parameter in the component "CkeditorUploadController.java".
CVE-2018-19178
- EPSS 0.56%
- Veröffentlicht 11.11.2018 16:29:00
- Zuletzt bearbeitet 21.11.2024 03:57:28
In JEESNS 1.3, com/lxinet/jeesns/core/utils/XssHttpServletRequestWrapper.java allows stored XSS via an HTML EMBED element, a different vulnerability than CVE-2018-17886.
CVE-2018-17886
- EPSS 0.66%
- Veröffentlicht 02.10.2018 18:29:02
- Zuletzt bearbeitet 21.11.2024 03:55:08
An issue was discovered in JEESNS 1.3. The XSS filter in com.lxinet.jeesns.core.utils.XssHttpServletRequestWrapper.java could be bypassed, as demonstrated by a <svg/onLoad=confirm substring. NOTE: this vulnerability exists because of an incomplete fi...