cmsuno project kayıtları
cmsuno project üreticisine ait 6 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-94 Improper Control of Generation of Code ('Code Injection')3
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-352 Cross-Site Request Forgery (CSRF)1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWESaldırı profili
Tüm kayıtlar
6 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2021-40889İstismar yok | CMSUno version 1.7.2 is affected by a PHP code execution vulnerability.cmsuno project · cmsuno · CWE-94 | Kritik9,8 | — | %1,8 | 11 Eki 2021 |
38İzleyin | CVE-2020-25538Kavram kanıtı | An authenticated attacker can inject malicious code into "lang" parameter in /uno/central.php file in CMSuno 1.6.2 and run this PHP code in cmsuno project · cmsuno · CWE-94 | Yüksek8,8 | — | %10,0 | 13 Kas 2020 |
38İzleyin | CVE-2020-25557Kavram kanıtı | In CMSuno 1.6.2, an attacker can inject malicious PHP code as a "username" while changing his/her username & password.cmsuno project · cmsuno · CWE-94 | Yüksek8,8 | — | %10,0 | 13 Kas 2020 |
27İzleyin | CVE-2020-15600Kavram kanıtı | An issue was discovered in CMSUno before 1.6.1.cmsuno project · cmsuno · CWE-352 | Orta6,5 | — | %1,9 | 7 Tem 2020 |
24İzleyin | CVE-2018-15567İstismar yok | CMSUno before 1.5.3 has XSS via the title field.cmsuno project · cmsuno · CWE-79 | Orta6,1 | — | %0,7 | 19 Ağu 2018 |
22İzleyin | CVE-2021-36654Kavram kanıtı | CMSuno 1.7 is vulnerable to an authenticated stored cross site scripting in modifying the filename parameter (tgo) while updating the theme.cmsuno project · cmsuno · CWE-79 | Orta5,4 | — | %1,9 | 3 Ağu 2021 |
- CVE-2021-4088940Planlayın
CMSUno version 1.7.2 is affected by a PHP code execution vulnerability.
KritikCVSS 9,8İstismar yokEPSS %2cmsuno project · cmsuno11 Eki 2021
- CVE-2020-2553838İzleyin
An authenticated attacker can inject malicious code into "lang" parameter in /uno/central.php file in CMSuno 1.6.2 and run this PHP code in
YüksekCVSS 8,8Kavram kanıtıEPSS %10cmsuno project · cmsuno13 Kas 2020
- CVE-2020-2555738İzleyin
In CMSuno 1.6.2, an attacker can inject malicious PHP code as a "username" while changing his/her username & password.
YüksekCVSS 8,8Kavram kanıtıEPSS %10cmsuno project · cmsuno13 Kas 2020
- CVE-2020-1560027İzleyin
An issue was discovered in CMSUno before 1.6.1.
OrtaCVSS 6,5Kavram kanıtıEPSS %2cmsuno project · cmsuno7 Tem 2020
- CVE-2018-1556724İzleyin
CMSUno before 1.5.3 has XSS via the title field.
OrtaCVSS 6,1İstismar yokEPSS %1cmsuno project · cmsuno19 Ağu 2018
- CVE-2021-3665422İzleyin
CMSuno 1.7 is vulnerable to an authenticated stored cross site scripting in modifying the filename parameter (tgo) while updating the theme.
OrtaCVSS 5,4Kavram kanıtıEPSS %2cmsuno project · cmsuno3 Ağu 2021