Перейти к содержимому
Noroxi

Записи dzzoffice

14 опубликованных записей вендора dzzoffice.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
0 · 0 %
Pre-auth RCE
2
С записью об исправлении
0 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Все записи

14 записей
  • CVE-2025-63695
    39Наблюдать

    DzzOffice v2.3.7 and before is vulnerable to Arbitrary File Upload in /dzz/system/ueditor/php/controller.php.

    КритическаяCVSS 9,8Эксплойта нетEPSS 0 %

    dzzoffice · dzzoffice18 нояб. 2025 г.

  • CVE-2025-63694
    39Наблюдать

    DzzOffice v2.3.7 and before is vulnerable to SQL Injection in explorer/groupmanage.

    КритическаяCVSS 9,8Эксплойта нетEPSS 0 %

    dzzoffice · dzzoffice18 нояб. 2025 г.

  • CVE-2024-41376
    35Наблюдать

    dzzoffice 2.02.1 is vulnerable to Directory Traversal via user/space/about.php.

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    dzzoffice · dzzoffice5 авг. 2024 г.

  • CVE-2022-43340
    35Наблюдать

    A Cross-Site Request Forgery (CSRF) in dzzoffice 2.02.1_SC_UTF8 allows attackers to arbitrarily create user accounts and grant Administrator

    ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %

    dzzoffice · dzzoffice27 окт. 2022 г.

  • CVE-2023-39853
    26Наблюдать

    SQL Injection vulnerability in Dzzoffice version 2.01, allows remote attackers to obtain sensitive information via the doobj and doevent par

    СредняяCVSS 6,5Эксплойта нетEPSS 1 %

    dzzoffice · dzzoffice6 янв. 2024 г.

  • CVE-2021-3318
    25Наблюдать

    attach/ajax.php in DzzOffice through 2.02.1 allows XSS via the editorid parameter.

    СредняяCVSS 6,1Proof of conceptEPSS 3 %

    dzzoffice · dzzoffice27 янв. 2021 г.

  • CVE-2020-19703
    24Наблюдать

    A cross-site scripting (XSS) vulnerability in the referer parameter of Dzzoffice 2.02 allows attackers to execute arbitrary web scripts or H

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    dzzoffice · dzzoffice25 авг. 2021 г.

  • CVE-2021-43673
    24Наблюдать

    dzzoffice 2.02.1_SC_UTF8 is affected by a Cross Site Scripting (XSS) vulnerability in explorerfile.php.

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    dzzoffice · dzzoffice3 дек. 2021 г.

  • CVE-2021-30203
    24Наблюдать

    A reflected cross-site scripting (XSS) vulnerability in the zero parameter of dzzoffice 2.02.1_SC_UTF8 allows attackers to execute arbitrary

    СредняяCVSS 6,1Proof of conceptEPSS 1 %

    dzzoffice · dzzoffice27 июн. 2023 г.

  • CVE-2024-29273
    24Наблюдать

    There is Stored Cross-Site Scripting (XSS) in dzzoffice 2.02.1 SC UTF8 in uploadfile to index.php, with the XSS payload in an SVG document.

    СредняяCVSS 6,1Эксплойта нетEPSS 0 %

    dzzoffice · dzzoffice22 мар. 2024 г.

  • CVE-2021-40292
    21Наблюдать

    A Stored Cross Site Sripting (XSS) vulnerability exists in DzzOffice 2.02.1 via the settingnew parameter.

    СредняяCVSS 5,4Эксплойта нетEPSS 1 %

    dzzoffice · dzzoffice12 окт. 2021 г.

  • CVE-2021-30205
    21Наблюдать

    Incorrect access control in the component /index.php?mod=system&op=orgtree of dzzoffice 2.02.1_SC_UTF8 allows unauthenticated attackers to b

    СредняяCVSS 5,3Эксплойта нетEPSS 1 %

    dzzoffice · dzzoffice27 июн. 2023 г.

  • CVE-2021-40191
    21Наблюдать

    Dzzoffice Version 2.02.1 is affected by cross-site scripting (XSS) due to a lack of sanitization of input data at all upload functions in we

    СредняяCVSS 5,4Эксплойта нетEPSS 1 %

    dzzoffice · dzzoffice11 окт. 2021 г.

  • CVE-2025-63693
    21Наблюдать

    The comment editing template (dzz/comment/template/edit_form.htm) in DzzOffice 2.3.x lacks adequate security escaping for user-controllable

    СредняяCVSS 5,4Эксплойта нетEPSS 0 %

    dzzoffice · dzzoffice18 нояб. 2025 г.