dzzoffice kayıtları
dzzoffice üreticisine ait 14 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 2
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')7
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-434 Unrestricted Upload of File with Dangerous Type1
- CWE-31 Path Traversal: 'dir\..\..\filename'1
- CWE-863 Incorrect Authorization1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
14 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
39İzleyin | CVE-2025-63695İstismar yok | DzzOffice v2.3.7 and before is vulnerable to Arbitrary File Upload in /dzz/system/ueditor/php/controller.php.dzzoffice · dzzoffice · CWE-434 | Kritik9,8 | — | %0,4 | 18 Kas 2025 |
39İzleyin | CVE-2025-63694İstismar yok | DzzOffice v2.3.7 and before is vulnerable to SQL Injection in explorer/groupmanage.dzzoffice · dzzoffice · CWE-89 | Kritik9,8 | — | %0,4 | 18 Kas 2025 |
35İzleyin | CVE-2024-41376İstismar yok | dzzoffice 2.02.1 is vulnerable to Directory Traversal via user/space/about.php.dzzoffice · dzzoffice · CWE-31 | Yüksek8,8 | — | %1,0 | 5 Ağu 2024 |
35İzleyin | CVE-2022-43340İstismar yok | A Cross-Site Request Forgery (CSRF) in dzzoffice 2.02.1_SC_UTF8 allows attackers to arbitrarily create user accounts and grant Administratordzzoffice · dzzoffice · CWE-352 | Yüksek8,8 | — | %0,4 | 27 Eki 2022 |
26İzleyin | CVE-2023-39853İstismar yok | SQL Injection vulnerability in Dzzoffice version 2.01, allows remote attackers to obtain sensitive information via the doobj and doevent pardzzoffice · dzzoffice · CWE-89 | Orta6,5 | — | %0,7 | 6 Oca 2024 |
25İzleyin | CVE-2021-3318Kavram kanıtı | attach/ajax.php in DzzOffice through 2.02.1 allows XSS via the editorid parameter.dzzoffice · dzzoffice · CWE-79 | Orta6,1 | — | %2,8 | 27 Oca 2021 |
24İzleyin | CVE-2020-19703İstismar yok | A cross-site scripting (XSS) vulnerability in the referer parameter of Dzzoffice 2.02 allows attackers to execute arbitrary web scripts or Hdzzoffice · dzzoffice · CWE-79 | Orta6,1 | — | %0,7 | 25 Ağu 2021 |
24İzleyin | CVE-2021-43673İstismar yok | dzzoffice 2.02.1_SC_UTF8 is affected by a Cross Site Scripting (XSS) vulnerability in explorerfile.php.dzzoffice · dzzoffice · CWE-79 | Orta6,1 | — | %0,6 | 3 Ara 2021 |
24İzleyin | CVE-2021-30203Kavram kanıtı | A reflected cross-site scripting (XSS) vulnerability in the zero parameter of dzzoffice 2.02.1_SC_UTF8 allows attackers to execute arbitrarydzzoffice · dzzoffice · CWE-79 | Orta6,1 | — | %0,6 | 27 Haz 2023 |
24İzleyin | CVE-2024-29273İstismar yok | There is Stored Cross-Site Scripting (XSS) in dzzoffice 2.02.1 SC UTF8 in uploadfile to index.php, with the XSS payload in an SVG document.dzzoffice · dzzoffice · CWE-79 | Orta6,1 | — | %0,4 | 22 Mar 2024 |
21İzleyin | CVE-2021-40292İstismar yok | A Stored Cross Site Sripting (XSS) vulnerability exists in DzzOffice 2.02.1 via the settingnew parameter.dzzoffice · dzzoffice · CWE-79 | Orta5,4 | — | %0,5 | 12 Eki 2021 |
21İzleyin | CVE-2021-30205İstismar yok | Incorrect access control in the component /index.php?mod=system&op=orgtree of dzzoffice 2.02.1_SC_UTF8 allows unauthenticated attackers to bdzzoffice · dzzoffice · CWE-863 | Orta5,3 | — | %0,5 | 27 Haz 2023 |
21İzleyin | CVE-2021-40191İstismar yok | Dzzoffice Version 2.02.1 is affected by cross-site scripting (XSS) due to a lack of sanitization of input data at all upload functions in wedzzoffice · dzzoffice · CWE-79 | Orta5,4 | — | %0,5 | 11 Eki 2021 |
21İzleyin | CVE-2025-63693İstismar yok | The comment editing template (dzz/comment/template/edit_form.htm) in DzzOffice 2.3.x lacks adequate security escaping for user-controllable dzzoffice · dzzoffice · CWE-94 | Orta5,4 | — | %0,2 | 18 Kas 2025 |
- CVE-2025-6369539İzleyin
DzzOffice v2.3.7 and before is vulnerable to Arbitrary File Upload in /dzz/system/ueditor/php/controller.php.
KritikCVSS 9,8İstismar yokEPSS %0dzzoffice · dzzoffice18 Kas 2025
- CVE-2025-6369439İzleyin
DzzOffice v2.3.7 and before is vulnerable to SQL Injection in explorer/groupmanage.
KritikCVSS 9,8İstismar yokEPSS %0dzzoffice · dzzoffice18 Kas 2025
- CVE-2024-4137635İzleyin
dzzoffice 2.02.1 is vulnerable to Directory Traversal via user/space/about.php.
YüksekCVSS 8,8İstismar yokEPSS %1dzzoffice · dzzoffice5 Ağu 2024
- CVE-2022-4334035İzleyin
A Cross-Site Request Forgery (CSRF) in dzzoffice 2.02.1_SC_UTF8 allows attackers to arbitrarily create user accounts and grant Administrator
YüksekCVSS 8,8İstismar yokEPSS %0dzzoffice · dzzoffice27 Eki 2022
- CVE-2023-3985326İzleyin
SQL Injection vulnerability in Dzzoffice version 2.01, allows remote attackers to obtain sensitive information via the doobj and doevent par
OrtaCVSS 6,5İstismar yokEPSS %1dzzoffice · dzzoffice6 Oca 2024
- CVE-2021-331825İzleyin
attach/ajax.php in DzzOffice through 2.02.1 allows XSS via the editorid parameter.
OrtaCVSS 6,1Kavram kanıtıEPSS %3dzzoffice · dzzoffice27 Oca 2021
- CVE-2020-1970324İzleyin
A cross-site scripting (XSS) vulnerability in the referer parameter of Dzzoffice 2.02 allows attackers to execute arbitrary web scripts or H
OrtaCVSS 6,1İstismar yokEPSS %1dzzoffice · dzzoffice25 Ağu 2021
- CVE-2021-4367324İzleyin
dzzoffice 2.02.1_SC_UTF8 is affected by a Cross Site Scripting (XSS) vulnerability in explorerfile.php.
OrtaCVSS 6,1İstismar yokEPSS %1dzzoffice · dzzoffice3 Ara 2021
- CVE-2021-3020324İzleyin
A reflected cross-site scripting (XSS) vulnerability in the zero parameter of dzzoffice 2.02.1_SC_UTF8 allows attackers to execute arbitrary
OrtaCVSS 6,1Kavram kanıtıEPSS %1dzzoffice · dzzoffice27 Haz 2023
- CVE-2024-2927324İzleyin
There is Stored Cross-Site Scripting (XSS) in dzzoffice 2.02.1 SC UTF8 in uploadfile to index.php, with the XSS payload in an SVG document.
OrtaCVSS 6,1İstismar yokEPSS %0dzzoffice · dzzoffice22 Mar 2024
- CVE-2021-4029221İzleyin
A Stored Cross Site Sripting (XSS) vulnerability exists in DzzOffice 2.02.1 via the settingnew parameter.
OrtaCVSS 5,4İstismar yokEPSS %1dzzoffice · dzzoffice12 Eki 2021
- CVE-2021-3020521İzleyin
Incorrect access control in the component /index.php?mod=system&op=orgtree of dzzoffice 2.02.1_SC_UTF8 allows unauthenticated attackers to b
OrtaCVSS 5,3İstismar yokEPSS %1dzzoffice · dzzoffice27 Haz 2023
- CVE-2021-4019121İzleyin
Dzzoffice Version 2.02.1 is affected by cross-site scripting (XSS) due to a lack of sanitization of input data at all upload functions in we
OrtaCVSS 5,4İstismar yokEPSS %1dzzoffice · dzzoffice11 Eki 2021
- CVE-2025-6369321İzleyin
The comment editing template (dzz/comment/template/edit_form.htm) in DzzOffice 2.3.x lacks adequate security escaping for user-controllable
OrtaCVSS 5,4İstismar yokEPSS %0dzzoffice · dzzoffice18 Kas 2025