İçeriğe atla
Noroxi

dzzoffice kayıtları

dzzoffice üreticisine ait 14 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
2
Düzeltme kaydı olan
%0
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

14 kayıt
  • CVE-2025-63695
    39İzleyin

    DzzOffice v2.3.7 and before is vulnerable to Arbitrary File Upload in /dzz/system/ueditor/php/controller.php.

    KritikCVSS 9,8İstismar yokEPSS %0

    dzzoffice · dzzoffice18 Kas 2025

  • CVE-2025-63694
    39İzleyin

    DzzOffice v2.3.7 and before is vulnerable to SQL Injection in explorer/groupmanage.

    KritikCVSS 9,8İstismar yokEPSS %0

    dzzoffice · dzzoffice18 Kas 2025

  • CVE-2024-41376
    35İzleyin

    dzzoffice 2.02.1 is vulnerable to Directory Traversal via user/space/about.php.

    YüksekCVSS 8,8İstismar yokEPSS %1

    dzzoffice · dzzoffice5 Ağu 2024

  • CVE-2022-43340
    35İzleyin

    A Cross-Site Request Forgery (CSRF) in dzzoffice 2.02.1_SC_UTF8 allows attackers to arbitrarily create user accounts and grant Administrator

    YüksekCVSS 8,8İstismar yokEPSS %0

    dzzoffice · dzzoffice27 Eki 2022

  • CVE-2023-39853
    26İzleyin

    SQL Injection vulnerability in Dzzoffice version 2.01, allows remote attackers to obtain sensitive information via the doobj and doevent par

    OrtaCVSS 6,5İstismar yokEPSS %1

    dzzoffice · dzzoffice6 Oca 2024

  • CVE-2021-3318
    25İzleyin

    attach/ajax.php in DzzOffice through 2.02.1 allows XSS via the editorid parameter.

    OrtaCVSS 6,1Kavram kanıtıEPSS %3

    dzzoffice · dzzoffice27 Oca 2021

  • CVE-2020-19703
    24İzleyin

    A cross-site scripting (XSS) vulnerability in the referer parameter of Dzzoffice 2.02 allows attackers to execute arbitrary web scripts or H

    OrtaCVSS 6,1İstismar yokEPSS %1

    dzzoffice · dzzoffice25 Ağu 2021

  • CVE-2021-43673
    24İzleyin

    dzzoffice 2.02.1_SC_UTF8 is affected by a Cross Site Scripting (XSS) vulnerability in explorerfile.php.

    OrtaCVSS 6,1İstismar yokEPSS %1

    dzzoffice · dzzoffice3 Ara 2021

  • CVE-2021-30203
    24İzleyin

    A reflected cross-site scripting (XSS) vulnerability in the zero parameter of dzzoffice 2.02.1_SC_UTF8 allows attackers to execute arbitrary

    OrtaCVSS 6,1Kavram kanıtıEPSS %1

    dzzoffice · dzzoffice27 Haz 2023

  • CVE-2024-29273
    24İzleyin

    There is Stored Cross-Site Scripting (XSS) in dzzoffice 2.02.1 SC UTF8 in uploadfile to index.php, with the XSS payload in an SVG document.

    OrtaCVSS 6,1İstismar yokEPSS %0

    dzzoffice · dzzoffice22 Mar 2024

  • CVE-2021-40292
    21İzleyin

    A Stored Cross Site Sripting (XSS) vulnerability exists in DzzOffice 2.02.1 via the settingnew parameter.

    OrtaCVSS 5,4İstismar yokEPSS %1

    dzzoffice · dzzoffice12 Eki 2021

  • CVE-2021-30205
    21İzleyin

    Incorrect access control in the component /index.php?mod=system&op=orgtree of dzzoffice 2.02.1_SC_UTF8 allows unauthenticated attackers to b

    OrtaCVSS 5,3İstismar yokEPSS %1

    dzzoffice · dzzoffice27 Haz 2023

  • CVE-2021-40191
    21İzleyin

    Dzzoffice Version 2.02.1 is affected by cross-site scripting (XSS) due to a lack of sanitization of input data at all upload functions in we

    OrtaCVSS 5,4İstismar yokEPSS %1

    dzzoffice · dzzoffice11 Eki 2021

  • CVE-2025-63693
    21İzleyin

    The comment editing template (dzz/comment/template/edit_form.htm) in DzzOffice 2.3.x lacks adequate security escaping for user-controllable

    OrtaCVSS 5,4İstismar yokEPSS %0

    dzzoffice · dzzoffice18 Kas 2025