CVE-2023-1798
- EPSS 0.34%
- Veröffentlicht 02.04.2023 10:15:07
- Zuletzt bearbeitet 21.11.2024 07:39:55
A vulnerability, which was classified as problematic, has been found in EyouCMS up to 1.5.4. Affected by this issue is some unknown functionality of the file login.php. The manipulation of the argument typename leads to cross site scripting. The atta...
CVE-2022-45755
- EPSS 0.56%
- Veröffentlicht 08.02.2023 19:15:11
- Zuletzt bearbeitet 25.03.2025 15:15:16
Cross-site scripting (XSS) vulnerability in EyouCMS v1.6.0 allows attackers to execute arbitrary code via the home page description on the basic information page.
CVE-2022-45538
- EPSS 0.29%
- Veröffentlicht 20.01.2023 19:15:16
- Zuletzt bearbeitet 03.04.2025 16:15:24
EyouCMS <= 1.6.0 was discovered a reflected-XSS in the article publish component in cookie "ENV_GOBACK_URL".
CVE-2022-45537
- EPSS 0.29%
- Veröffentlicht 20.01.2023 19:15:16
- Zuletzt bearbeitet 03.04.2025 16:15:23
EyouCMS <= 1.6.0 was discovered a reflected-XSS in the article publish component in cookie "ENV_LIST_URL".
CVE-2022-45539
- EPSS 0.27%
- Veröffentlicht 20.01.2023 19:15:16
- Zuletzt bearbeitet 03.04.2025 16:15:24
EyouCMS <= 1.6.0 was discovered a reflected-XSS in FileManager component in GET value "activepath" when creating a new file.
CVE-2022-45540
- EPSS 0.27%
- Veröffentlicht 20.01.2023 19:15:16
- Zuletzt bearbeitet 03.04.2025 16:15:24
EyouCMS <= 1.6.0 was discovered a reflected-XSS in article type editor component in POST value "name" if the value contains a malformed UTF-8 char.
CVE-2022-45541
- EPSS 0.27%
- Veröffentlicht 20.01.2023 19:15:16
- Zuletzt bearbeitet 03.04.2025 16:15:24
EyouCMS <= 1.6.0 was discovered a reflected-XSS in the article attribute editor component in POST value "value" if the value contains a non-integer char.
CVE-2022-45542
- EPSS 0.29%
- Veröffentlicht 20.01.2023 19:15:16
- Zuletzt bearbeitet 03.04.2025 16:15:24
EyouCMS <= 1.6.0 was discovered a reflected-XSS in the FileManager component in GET parameter "filename" when editing any file.
CVE-2021-39428
- EPSS 0.18%
- Veröffentlicht 15.12.2022 19:15:16
- Zuletzt bearbeitet 21.04.2025 19:15:16
Cross Site Scripting (XSS) vulnerability in Users.php in eyoucms 1.5.4 allows remote attackers to run arbitrary code and gain escalated privilege via the filename for edit_users_head_pic.
CVE-2022-45280
- EPSS 0.2%
- Veröffentlicht 23.11.2022 21:15:11
- Zuletzt bearbeitet 25.04.2025 20:15:37
A cross-site scripting (XSS) vulnerability in the Url parameter in /login.php of EyouCMS v1.6.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.