Security
Headlines
HeadlinesLatestCVEs

Tag

#git

CVE-2020-23595: CSRF Vulnerability in v5.6 · Issue #47 · yzmcms/yzmcms

Cross Site Request Forgery (CSRF) vulnerability in yzmcms version 5.6, allows remote attackers to escalate privileges and gain sensitive information sitemodel/add.html endpoint.

CVE
#csrf#vulnerability#git
CVE-2020-24804: There are multiple information leaks in cms-dev/cms · Issue #1160 · cms-dev/cms

Plaintext Password vulnerability in AddAdmin.py in cms-dev/cms v1.4.rc1, allows attackers to gain sensitive information via audit logs.

CVE-2021-29378: pear-admin-think V2.1.2 has a sql injection vulnerability · Issue #I3DIEC · Pear Admin/Pear Admin Think - Gitee.com

SQL Injection in pear-admin-think version 2.1.2, allows attackers to execute arbitrary code and escalate privileges via crafted GET request to Crud.php.

CVE-2021-28411: Wrong code modification leads to Shiro deserialization vulnerability · Issue #20 · lerry903/RuoYi

An issue was discovered in getRememberedSerializedIdentity function in CookieRememberMeManager class in lerry903 RuoYi version 3.4.0, allows remote attackers to escalate privileges.

CVE-2020-19952: XSS vulnerability on <abbr> and <sup><EMBED> label · Issue #106 · jbt/markdown-editor

Cross Site Scripting (XSS) vulnerability in Rendering Engine in jbt Markdown Editor thru commit 2252418c27dffbb35147acd8ed324822b8919477, allows remote attackers to execute arbirary code via crafted payload or opening malicious .md file.

CVE-2020-27514: Arbitrary File Deletion Vulnerability in com.zrlog.web.controller.admin.api.TemplateController#delete · Issue #66 · 94fzb/zrlog

Directory Traversal vulnerability in delete function in admin.api.TemplateController in ZrLog version 2.1.15, allows remote attackers to delete arbitrary files and cause a denial of service (DoS).

CVE-2020-28717: XSS vulnerability in demo.jsp · Issue #321 · kindsoft/kindeditor

Cross Site Scripting (XSS) vulnerability in content1 parameter in demo.jsp in kindsoft kindeditor version 4.1.12, allows attackers to execute arbitrary code.

CVE-2020-24922: There is a CSRF vulnerability that can add the administrator account · Issue #1921 · xuxueli/xxl-job

Cross Site Request Forgery (CSRF) vulnerability in xxl-job-admin/user/add in xuxueli xxl-job version 2.2.0, allows remote attackers to execute arbitrary code and esclate privileges via crafted .html file.

CVE-2020-36136: Bug Report: SQL injection vulnerability · Issue #26 · cskaza/cszcms

SQL Injection vulnerability in cskaza cszcms version 1.2.9, allows attackers to gain sensitive information via pm_sendmail parameter in csz_model.php.