3 results (0.023 seconds)

CVSS: 5.4EPSS: 0%CPEs: 1EXPL: 3

Evolution CMS 2.0.x allows XSS via a description and new category location in a template. NOTE: the vendor states that the behavior is consistent with the "access policy in the administration panel. ** EN DISPUTA ** Evolution CMS 2.0.x permite XSS a través de una descripción y una nueva ubicación de categoría en una plantilla. NOTA: el proveedor indica que el comportamiento es consistente con la "política de acceso en el panel de administración" • https://github.com/evolution-cms/evolution/issues/1041 https://github.com/evolution-cms/evolution/issues/1042 https://github.com/evolution-cms/evolution/issues/1043 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 5.4EPSS: 0%CPEs: 1EXPL: 1

Evolution CMS 1.4.x allows XSS via the page weblink title parameter to the manager/ URI. Evolution CMS 1.4.x permite Cross-Site Scripting (XSS) mediante el parámetro title en el weblink de la página en el URI manager/. • https://github.com/security-breachlock/CVE-2018-16637/blob/master/evolution_xss_stored.pdf • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 5.4EPSS: 0%CPEs: 1EXPL: 1

Evolution CMS 1.4.x allows XSS via the manager/ search parameter. Evolution CMS 1.4.x permite Cross-Site Scripting (XSS) mediante el parámetro search en manager/. • https://github.com/security-breachlock/CVE-2018-16638/blob/master/evolution_xss_reflected.pdf • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •