CVE-2022-44389
- EPSS 0.1%
- Veröffentlicht 14.11.2022 20:15:18
- Zuletzt bearbeitet 30.04.2025 19:15:53
EyouCMS V1.5.9-UTF8-SP1 was discovered to contain a Cross-Site Request Forgery (CSRF) via the Edit Admin Profile module. This vulnerability allows attackers to arbitrarily change Administrator account information.
CVE-2022-44387
- EPSS 0.11%
- Veröffentlicht 14.11.2022 20:15:18
- Zuletzt bearbeitet 30.04.2025 19:15:52
EyouCMS V1.5.9-UTF8-SP1 was discovered to contain a Cross-Site Request Forgery (CSRF) via the Basic Information component under the Edit Member module.
CVE-2022-43323
- EPSS 0.13%
- Veröffentlicht 14.11.2022 20:15:17
- Zuletzt bearbeitet 30.04.2025 16:15:27
EyouCMS V1.5.9-UTF8-SP1 was discovered to contain a Cross-Site Request Forgery (CSRF) via the Top Up Balance component under the Edit Member module.
CVE-2022-41500
- EPSS 0.09%
- Veröffentlicht 18.10.2022 23:15:09
- Zuletzt bearbeitet 15.05.2025 16:15:29
EyouCMS V1.5.9 was discovered to contain multiple Cross-Site Request Forgery (CSRF) vulnerabilities via the Members Center, Editorial Membership, and Points Recharge components.
CVE-2022-36225
- EPSS 0.21%
- Veröffentlicht 19.08.2022 17:15:07
- Zuletzt bearbeitet 21.11.2024 07:12:37
EyouCMS V1.5.8-UTF8-SP1 is vulnerable to Cross Site Request Forgery (CSRF) via the background, column management function and add.
CVE-2022-35509
- EPSS 0.22%
- Veröffentlicht 10.08.2022 20:15:54
- Zuletzt bearbeitet 21.11.2024 07:11:16
An issue was discovered in EyouCMS 1.5.8. There is a Storage XSS vulnerability that can allows an attacker to execute arbitrary Web scripts or HTML by injecting a special payload via the title parameter in the foreground contribution, allowing the at...
CVE-2022-33122
- EPSS 0.22%
- Veröffentlicht 24.06.2022 21:15:08
- Zuletzt bearbeitet 21.11.2024 07:07:34
A stored cross-site scripting (XSS) vulnerability in eyoucms v1.5.6 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the URL field under the login page.
CVE-2022-26273
- EPSS 0.43%
- Veröffentlicht 28.03.2022 02:15:07
- Zuletzt bearbeitet 21.11.2024 06:53:40
EyouCMS v1.5.4 was discovered to lack parameter filtering in \user\controller\shop.php, leading to payment logic vulnerabilities.
CVE-2022-26279
- EPSS 0.99%
- Veröffentlicht 24.03.2022 22:15:09
- Zuletzt bearbeitet 21.11.2024 06:53:41
EyouCMS v1.5.5 was discovered to have no access control in the component /data/sqldata.
CVE-2021-42194
- EPSS 0.34%
- Veröffentlicht 20.03.2022 22:15:07
- Zuletzt bearbeitet 21.11.2024 06:27:22
The wechat_return function in /controller/Index.php of EyouCms V1.5.4-UTF8-SP3 passes the user's input directly into the simplexml_ load_ String function, which itself does not prohibit external entities, triggering a XML external entity (XXE) inject...