Eyoucms

Eyoucms

75 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.1%
  • Veröffentlicht 14.11.2022 20:15:18
  • Zuletzt bearbeitet 30.04.2025 19:15:53

EyouCMS V1.5.9-UTF8-SP1 was discovered to contain a Cross-Site Request Forgery (CSRF) via the Edit Admin Profile module. This vulnerability allows attackers to arbitrarily change Administrator account information.

  • EPSS 0.11%
  • Veröffentlicht 14.11.2022 20:15:18
  • Zuletzt bearbeitet 30.04.2025 19:15:52

EyouCMS V1.5.9-UTF8-SP1 was discovered to contain a Cross-Site Request Forgery (CSRF) via the Basic Information component under the Edit Member module.

Exploit
  • EPSS 0.13%
  • Veröffentlicht 14.11.2022 20:15:17
  • Zuletzt bearbeitet 30.04.2025 16:15:27

EyouCMS V1.5.9-UTF8-SP1 was discovered to contain a Cross-Site Request Forgery (CSRF) via the Top Up Balance component under the Edit Member module.

Exploit
  • EPSS 0.09%
  • Veröffentlicht 18.10.2022 23:15:09
  • Zuletzt bearbeitet 15.05.2025 16:15:29

EyouCMS V1.5.9 was discovered to contain multiple Cross-Site Request Forgery (CSRF) vulnerabilities via the Members Center, Editorial Membership, and Points Recharge components.

Exploit
  • EPSS 0.21%
  • Veröffentlicht 19.08.2022 17:15:07
  • Zuletzt bearbeitet 21.11.2024 07:12:37

EyouCMS V1.5.8-UTF8-SP1 is vulnerable to Cross Site Request Forgery (CSRF) via the background, column management function and add.

Exploit
  • EPSS 0.22%
  • Veröffentlicht 10.08.2022 20:15:54
  • Zuletzt bearbeitet 21.11.2024 07:11:16

An issue was discovered in EyouCMS 1.5.8. There is a Storage XSS vulnerability that can allows an attacker to execute arbitrary Web scripts or HTML by injecting a special payload via the title parameter in the foreground contribution, allowing the at...

Exploit
  • EPSS 0.22%
  • Veröffentlicht 24.06.2022 21:15:08
  • Zuletzt bearbeitet 21.11.2024 07:07:34

A stored cross-site scripting (XSS) vulnerability in eyoucms v1.5.6 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the URL field under the login page.

  • EPSS 0.43%
  • Veröffentlicht 28.03.2022 02:15:07
  • Zuletzt bearbeitet 21.11.2024 06:53:40

EyouCMS v1.5.4 was discovered to lack parameter filtering in \user\controller\shop.php, leading to payment logic vulnerabilities.

Exploit
  • EPSS 0.99%
  • Veröffentlicht 24.03.2022 22:15:09
  • Zuletzt bearbeitet 21.11.2024 06:53:41

EyouCMS v1.5.5 was discovered to have no access control in the component /data/sqldata.

Exploit
  • EPSS 0.34%
  • Veröffentlicht 20.03.2022 22:15:07
  • Zuletzt bearbeitet 21.11.2024 06:27:22

The wechat_return function in /controller/Index.php of EyouCms V1.5.4-UTF8-SP3 passes the user's input directly into the simplexml_ load_ String function, which itself does not prohibit external entities, triggering a XML external entity (XXE) inject...