Записи dzzoffice
14 опубликованных записей вендора dzzoffice.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 2
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')7
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-434 Unrestricted Upload of File with Dangerous Type1
- CWE-31 Path Traversal: 'dir\..\..\filename'1
- CWE-863 Incorrect Authorization1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
14 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
39Наблюдать | CVE-2025-63695Эксплойта нет | DzzOffice v2.3.7 and before is vulnerable to Arbitrary File Upload in /dzz/system/ueditor/php/controller.php.dzzoffice · dzzoffice · CWE-434 | Критическая9,8 | — | 0,4 % | 18 нояб. 2025 г. |
39Наблюдать | CVE-2025-63694Эксплойта нет | DzzOffice v2.3.7 and before is vulnerable to SQL Injection in explorer/groupmanage.dzzoffice · dzzoffice · CWE-89 | Критическая9,8 | — | 0,4 % | 18 нояб. 2025 г. |
35Наблюдать | CVE-2024-41376Эксплойта нет | dzzoffice 2.02.1 is vulnerable to Directory Traversal via user/space/about.php.dzzoffice · dzzoffice · CWE-31 | Высокая8,8 | — | 1,0 % | 5 авг. 2024 г. |
35Наблюдать | CVE-2022-43340Эксплойта нет | A Cross-Site Request Forgery (CSRF) in dzzoffice 2.02.1_SC_UTF8 allows attackers to arbitrarily create user accounts and grant Administratordzzoffice · dzzoffice · CWE-352 | Высокая8,8 | — | 0,4 % | 27 окт. 2022 г. |
26Наблюдать | CVE-2023-39853Эксплойта нет | SQL Injection vulnerability in Dzzoffice version 2.01, allows remote attackers to obtain sensitive information via the doobj and doevent pardzzoffice · dzzoffice · CWE-89 | Средняя6,5 | — | 0,7 % | 6 янв. 2024 г. |
25Наблюдать | CVE-2021-3318Proof of concept | attach/ajax.php in DzzOffice through 2.02.1 allows XSS via the editorid parameter.dzzoffice · dzzoffice · CWE-79 | Средняя6,1 | — | 2,8 % | 27 янв. 2021 г. |
24Наблюдать | CVE-2020-19703Эксплойта нет | A cross-site scripting (XSS) vulnerability in the referer parameter of Dzzoffice 2.02 allows attackers to execute arbitrary web scripts or Hdzzoffice · dzzoffice · CWE-79 | Средняя6,1 | — | 0,7 % | 25 авг. 2021 г. |
24Наблюдать | CVE-2021-43673Эксплойта нет | dzzoffice 2.02.1_SC_UTF8 is affected by a Cross Site Scripting (XSS) vulnerability in explorerfile.php.dzzoffice · dzzoffice · CWE-79 | Средняя6,1 | — | 0,6 % | 3 дек. 2021 г. |
24Наблюдать | CVE-2021-30203Proof of concept | A reflected cross-site scripting (XSS) vulnerability in the zero parameter of dzzoffice 2.02.1_SC_UTF8 allows attackers to execute arbitrarydzzoffice · dzzoffice · CWE-79 | Средняя6,1 | — | 0,6 % | 27 июн. 2023 г. |
24Наблюдать | CVE-2024-29273Эксплойта нет | There is Stored Cross-Site Scripting (XSS) in dzzoffice 2.02.1 SC UTF8 in uploadfile to index.php, with the XSS payload in an SVG document.dzzoffice · dzzoffice · CWE-79 | Средняя6,1 | — | 0,4 % | 22 мар. 2024 г. |
21Наблюдать | CVE-2021-40292Эксплойта нет | A Stored Cross Site Sripting (XSS) vulnerability exists in DzzOffice 2.02.1 via the settingnew parameter.dzzoffice · dzzoffice · CWE-79 | Средняя5,4 | — | 0,5 % | 12 окт. 2021 г. |
21Наблюдать | CVE-2021-30205Эксплойта нет | Incorrect access control in the component /index.php?mod=system&op=orgtree of dzzoffice 2.02.1_SC_UTF8 allows unauthenticated attackers to bdzzoffice · dzzoffice · CWE-863 | Средняя5,3 | — | 0,5 % | 27 июн. 2023 г. |
21Наблюдать | CVE-2021-40191Эксплойта нет | Dzzoffice Version 2.02.1 is affected by cross-site scripting (XSS) due to a lack of sanitization of input data at all upload functions in wedzzoffice · dzzoffice · CWE-79 | Средняя5,4 | — | 0,5 % | 11 окт. 2021 г. |
21Наблюдать | CVE-2025-63693Эксплойта нет | The comment editing template (dzz/comment/template/edit_form.htm) in DzzOffice 2.3.x lacks adequate security escaping for user-controllable dzzoffice · dzzoffice · CWE-94 | Средняя5,4 | — | 0,2 % | 18 нояб. 2025 г. |
- CVE-2025-6369539Наблюдать
DzzOffice v2.3.7 and before is vulnerable to Arbitrary File Upload in /dzz/system/ueditor/php/controller.php.
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %dzzoffice · dzzoffice18 нояб. 2025 г.
- CVE-2025-6369439Наблюдать
DzzOffice v2.3.7 and before is vulnerable to SQL Injection in explorer/groupmanage.
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %dzzoffice · dzzoffice18 нояб. 2025 г.
- CVE-2024-4137635Наблюдать
dzzoffice 2.02.1 is vulnerable to Directory Traversal via user/space/about.php.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %dzzoffice · dzzoffice5 авг. 2024 г.
- CVE-2022-4334035Наблюдать
A Cross-Site Request Forgery (CSRF) in dzzoffice 2.02.1_SC_UTF8 allows attackers to arbitrarily create user accounts and grant Administrator
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %dzzoffice · dzzoffice27 окт. 2022 г.
- CVE-2023-3985326Наблюдать
SQL Injection vulnerability in Dzzoffice version 2.01, allows remote attackers to obtain sensitive information via the doobj and doevent par
СредняяCVSS 6,5Эксплойта нетEPSS 1 %dzzoffice · dzzoffice6 янв. 2024 г.
- CVE-2021-331825Наблюдать
attach/ajax.php in DzzOffice through 2.02.1 allows XSS via the editorid parameter.
СредняяCVSS 6,1Proof of conceptEPSS 3 %dzzoffice · dzzoffice27 янв. 2021 г.
- CVE-2020-1970324Наблюдать
A cross-site scripting (XSS) vulnerability in the referer parameter of Dzzoffice 2.02 allows attackers to execute arbitrary web scripts or H
СредняяCVSS 6,1Эксплойта нетEPSS 1 %dzzoffice · dzzoffice25 авг. 2021 г.
- CVE-2021-4367324Наблюдать
dzzoffice 2.02.1_SC_UTF8 is affected by a Cross Site Scripting (XSS) vulnerability in explorerfile.php.
СредняяCVSS 6,1Эксплойта нетEPSS 1 %dzzoffice · dzzoffice3 дек. 2021 г.
- CVE-2021-3020324Наблюдать
A reflected cross-site scripting (XSS) vulnerability in the zero parameter of dzzoffice 2.02.1_SC_UTF8 allows attackers to execute arbitrary
СредняяCVSS 6,1Proof of conceptEPSS 1 %dzzoffice · dzzoffice27 июн. 2023 г.
- CVE-2024-2927324Наблюдать
There is Stored Cross-Site Scripting (XSS) in dzzoffice 2.02.1 SC UTF8 in uploadfile to index.php, with the XSS payload in an SVG document.
СредняяCVSS 6,1Эксплойта нетEPSS 0 %dzzoffice · dzzoffice22 мар. 2024 г.
- CVE-2021-4029221Наблюдать
A Stored Cross Site Sripting (XSS) vulnerability exists in DzzOffice 2.02.1 via the settingnew parameter.
СредняяCVSS 5,4Эксплойта нетEPSS 1 %dzzoffice · dzzoffice12 окт. 2021 г.
- CVE-2021-3020521Наблюдать
Incorrect access control in the component /index.php?mod=system&op=orgtree of dzzoffice 2.02.1_SC_UTF8 allows unauthenticated attackers to b
СредняяCVSS 5,3Эксплойта нетEPSS 1 %dzzoffice · dzzoffice27 июн. 2023 г.
- CVE-2021-4019121Наблюдать
Dzzoffice Version 2.02.1 is affected by cross-site scripting (XSS) due to a lack of sanitization of input data at all upload functions in we
СредняяCVSS 5,4Эксплойта нетEPSS 1 %dzzoffice · dzzoffice11 окт. 2021 г.
- CVE-2025-6369321Наблюдать
The comment editing template (dzz/comment/template/edit_form.htm) in DzzOffice 2.3.x lacks adequate security escaping for user-controllable
СредняяCVSS 5,4Эксплойта нетEPSS 0 %dzzoffice · dzzoffice18 нояб. 2025 г.