Jeesns

Jeesns

21 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.17%
  • Veröffentlicht 09.09.2021 23:15:09
  • Zuletzt bearbeitet 21.11.2024 05:09:06

A stored cross-site scripting (XSS) vulnerability in the /group/post component of Jeesns 1.4.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the title.

Exploit
  • EPSS 0.26%
  • Veröffentlicht 09.09.2021 23:15:09
  • Zuletzt bearbeitet 21.11.2024 05:09:05

A stored cross-site scripting (XSS) vulnerability in the /group/apply component of Jeesns 1.4.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the Name text field.

Exploit
  • EPSS 0.19%
  • Veröffentlicht 09.09.2021 23:15:09
  • Zuletzt bearbeitet 21.11.2024 05:09:05

A stored cross-site scripting (XSS) vulnerability in the /group/comment component of Jeesns 1.4.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the group comments text field.

Exploit
  • EPSS 2.55%
  • Veröffentlicht 09.09.2021 23:15:09
  • Zuletzt bearbeitet 21.11.2024 05:09:05

A reflected cross-site scripting (XSS) vulnerability in the /newVersion component of Jeesns 1.4.2 allows attackers to execute arbitrary web scripts or HTML.

Exploit
  • EPSS 6.61%
  • Veröffentlicht 09.09.2021 23:15:09
  • Zuletzt bearbeitet 21.11.2024 05:09:05

A reflected cross-site scripting (XSS) vulnerability in Jeesns 1.4.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the system error message's text field.

Exploit
  • EPSS 0.26%
  • Veröffentlicht 09.09.2021 23:15:09
  • Zuletzt bearbeitet 21.11.2024 05:09:05

A stored cross-site scripting (XSS) vulnerability in the /manage/loginusername component of Jeesns 1.4.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the username field.

Exploit
  • EPSS 0.88%
  • Veröffentlicht 09.09.2021 23:15:07
  • Zuletzt bearbeitet 21.11.2024 05:09:05

Jeesns 1.4.2 contains a cross-site request forgery (CSRF) which allows attackers to escalate privileges and perform sensitive program operations.

  • EPSS 0.43%
  • Veröffentlicht 29.04.2021 23:15:07
  • Zuletzt bearbeitet 21.11.2024 05:08:22

Cross Site Scripting (XSS) in Jeesns v1.4.2 allows remote attackers to execute arbitrary code by injecting commands into the "CKEditorFuncNum" parameter in the component "CkeditorUploadController.java".

Exploit
  • EPSS 0.28%
  • Veröffentlicht 11.11.2018 16:29:00
  • Zuletzt bearbeitet 21.11.2024 03:57:28

In JEESNS 1.3, com/lxinet/jeesns/core/utils/XssHttpServletRequestWrapper.java allows stored XSS via an HTML EMBED element, a different vulnerability than CVE-2018-17886.

Exploit
  • EPSS 0.21%
  • Veröffentlicht 02.10.2018 18:29:02
  • Zuletzt bearbeitet 21.11.2024 03:55:08

An issue was discovered in JEESNS 1.3. The XSS filter in com.lxinet.jeesns.core.utils.XssHttpServletRequestWrapper.java could be bypassed, as demonstrated by a <svg/onLoad=confirm substring. NOTE: this vulnerability exists because of an incomplete fi...