Wuzhicms

Wuzhicms

57 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.04%
  • Veröffentlicht 14.04.2025 11:00:12
  • Zuletzt bearbeitet 29.04.2025 20:25:59

A vulnerability was found in WuzhiCMS 4.1. It has been rated as critical. Affected by this issue is the function Set of the file /index.php?m=attachment&f=index&_su=wuzhicms&v=set&submit=1 of the component Setting Handler. The manipulation of the arg...

Exploit
  • EPSS 0.04%
  • Veröffentlicht 28.02.2025 15:15:13
  • Zuletzt bearbeitet 29.04.2025 16:53:21

wuzhicms v4.1.0 has a Cross Site Scripting (XSS) vulnerability in del function in \coreframe\app\member\admin\group.php.

Exploit
  • EPSS 0.08%
  • Veröffentlicht 15.01.2025 18:15:24
  • Zuletzt bearbeitet 13.05.2025 13:39:11

A vulnerability classified as problematic has been found in wuzhicms 4.1.0. This affects the function test of the file coreframe/app/search/admin/config.php. The manipulation of the argument sphinxhost/sphinxport leads to server-side request forgery....

Exploit
  • EPSS 0.28%
  • Veröffentlicht 30.10.2024 02:15:02
  • Zuletzt bearbeitet 06.11.2024 16:38:28

A vulnerability was found in wuzhicms 4.1.0. It has been classified as critical. Affected is the function add/edit of the file www/coreframe/app/content/admin/block.php. The manipulation leads to code injection. It is possible to launch the attack re...

Exploit
  • EPSS 0.23%
  • Veröffentlicht 19.04.2024 16:15:10
  • Zuletzt bearbeitet 05.05.2025 18:14:23

A stored cross-site scripting (XSS) vulnerability in the component \affiche\admin\index.php of WUZHICMS v4.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the $formdata parameter.

Exploit
  • EPSS 0.18%
  • Veröffentlicht 03.04.2024 06:15:07
  • Zuletzt bearbeitet 13.05.2025 01:10:52

An issue was discovered in WUZHICMS version 4.1.0, allows an attacker to execute arbitrary code and obtain sensitive information via the index.php file.

Exploit
  • EPSS 0.14%
  • Veröffentlicht 10.01.2024 21:15:09
  • Zuletzt bearbeitet 03.06.2025 15:15:49

Wuzhicms v4.1.0 was discovered to contain a SQL injection vulnerability via the $keywords parameter at /core/admin/copyfrom.php.

Exploit
  • EPSS 1.96%
  • Veröffentlicht 01.11.2023 19:15:45
  • Zuletzt bearbeitet 21.11.2024 08:28:34

SQL injection vulnerability in wuzhicms v.4.1.0 allows a remote attacker to execute arbitrary code via the Database Backup Functionality in the coreframe/app/database/admin/index.php component.

Exploit
  • EPSS 0.32%
  • Veröffentlicht 11.08.2023 14:15:11
  • Zuletzt bearbeitet 21.11.2024 05:28:41

An issue was disocvered in wuzhicms version 4.1.0, allows remote attackers to execte arbitrary code via the setting parameter to the ueditor in index.php.

Exploit
  • EPSS 1.09%
  • Veröffentlicht 20.06.2023 15:15:11
  • Zuletzt bearbeitet 09.12.2024 22:15:20

An issue in WUZHI CMS v.4.1.0 allows a remote attacker to execute arbitrary code via the set_chache method of the function\common.func.php file.