15 results (0.009 seconds)

CVSS: 5.4EPSS: 0%CPEs: 1EXPL: 1

Cross Site Scripting vulnerability in OFCMS v.1.14 allows a remote attacker to obtain sensitive information via a crafted payload to the title addition component. Una vulnerabilidad de cross site scripting en OFCMS v.1.14 permite a un atacante remoto obtener información confidencial a través de un payload manipulado para el componente title addition. • https://gitee.com/oufu/ofcms https://gitee.com/oufu/ofcms/issues/I7OAU2 https://github.com/Phantom4me/CVE-Management/blob/main/CVE-2023-51807.md • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 8.8EPSS: 0%CPEs: 1EXPL: 1

An issue found in Ofcms v.1.1.4 allows a remote attacker to to escalate privileges via the respwd method in SysUserController. • https://gitee.com/oufu/ofcms/issues/I6BD2Q https://gitee.com/oufu/ofcms/issues/I6L75S • CWE-269: Improper Privilege Management •

CVSS: 6.1EPSS: 0%CPEs: 1EXPL: 0

OFCMS v1.1.4 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /admin/comn/service/update.json. Se ha detectado que OFCMS versión v1.1.4, contiene una vulnerabilidad de tipo cross-site scripting (XSS) por medio del componente /admin/comn/service/update.json • https://gitee.com/oufu/ofcms/issues/I53COA • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 5.4EPSS: 0%CPEs: 1EXPL: 1

A cross-site scripting (XSS) vulnerability at /ofcms/company-c-47 in OFCMS v1.1.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Comment text box. Una vulnerabilidad de tipo cross-site scripting (XSS) en /ofcms/company-c-47 en OFCMS versión v1.1.4, permite a atacantes ejecutar scripts web o HTML arbitrarios por medio de una carga útil diseñada inyectada en el cuadro de texto de Comentarios • https://gitee.com/oufu/ofcms/issues/I4Z8QU • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 5.5EPSS: 0%CPEs: 1EXPL: 1

Insecure permissions configured in the user_id parameter at SysUserController.java of OFCMS v1.1.4 allows attackers to access and arbitrarily modify users' personal information. Unos permisos no seguros configurados en el parámetro user_id en SysUserController.java de OFCMS versión v1.1.4 permiten a atacantes acceder y modificar arbitrariamente la información personal de usuarios • https://gitee.com/oufu/ofcms/issues/I4Z8SS • CWE-276: Incorrect Default Permissions •