CVE-2020-19897
- EPSS 0.74%
- Veröffentlicht 28.06.2022 22:15:07
- Zuletzt bearbeitet 05.05.2025 18:10:51
A reflected Cross Site Scripting (XSS) in wuzhicms v4.1.0 allows remote attackers to execute arbitrary web script or HTML via the imgurl parameter.
CVE-2021-41654
- EPSS 1.03%
- Veröffentlicht 16.06.2022 12:15:10
- Zuletzt bearbeitet 21.11.2024 06:26:35
SQL injection vulnerabilities exist in Wuzhicms v4.1.0 which allows attackers to execute arbitrary SQL commands via the $keyValue parameter in /coreframe/app/pay/admin/index.php
CVE-2022-27431
- EPSS 1.06%
- Veröffentlicht 04.05.2022 03:15:07
- Zuletzt bearbeitet 05.05.2025 18:10:51
Wuzhicms v4.1.0 was discovered to contain a SQL injection vulnerability via the groupid parameter at /coreframe/app/member/admin/group.php.
CVE-2020-19770
- EPSS 0.49%
- Veröffentlicht 21.12.2021 18:15:07
- Zuletzt bearbeitet 05.05.2025 18:10:51
A cross-site scripting (XSS) vulnerability in the system bulletin component of WUZHI CMS v4.1.0 allows attackers to steal the admin's cookie.
CVE-2020-28145
- EPSS 1.25%
- Veröffentlicht 12.10.2021 11:15:07
- Zuletzt bearbeitet 21.11.2024 05:22:24
Arbitrary file deletion vulnerability was discovered in wuzhicms v 4.0.1 via coreframe\app\attachment\admin\index.php, which allows attackers to access sensitive information.
CVE-2020-20124
- EPSS 2.86%
- Veröffentlicht 28.09.2021 23:15:07
- Zuletzt bearbeitet 05.05.2025 18:10:51
Wuzhi CMS v4.1.0 contains a remote code execution (RCE) vulnerability in \attachment\admin\index.php.
CVE-2020-20122
- EPSS 1.28%
- Veröffentlicht 28.09.2021 23:15:07
- Zuletzt bearbeitet 05.05.2025 18:10:51
Wuzhi CMS v4.1 contains a SQL injection vulnerability in the checktitle() function in /coreframe/app/content/admin/content.php.
CVE-2020-24930
- EPSS 1.13%
- Veröffentlicht 27.09.2021 21:15:07
- Zuletzt bearbeitet 21.11.2024 05:16:13
Beijing Wuzhi Internet Technology Co., Ltd. Wuzhi CMS 4.0.1 is an open source content management system. The five fingers CMS backend in***.php file has arbitrary file deletion vulnerability. Attackers can use vulnerabilities to delete arbitrary file...
CVE-2020-19553
- EPSS 0.58%
- Veröffentlicht 21.09.2021 19:15:07
- Zuletzt bearbeitet 21.11.2024 05:09:14
Cross Site Scripting (XSS) vlnerability exists in WUZHI CMS up to and including 4.1.0 in the config function in coreframe/app/attachment/libs/class/ckditor.class.php.
CVE-2020-19551
- EPSS 1.76%
- Veröffentlicht 21.09.2021 19:15:07
- Zuletzt bearbeitet 21.11.2024 05:09:14
Blacklist bypass issue exists in WUZHI CMS up to and including 4.1.0 in common.func.php, which when uploaded can cause remote code executiong.