3 results (0.014 seconds)

CVSS: 8.8EPSS: 0%CPEs: 1EXPL: 1

A cross-site request forgery (CSRF) in /controller/pay.class.php of YzmCMS v5.5 allows attackers to access sensitive components of the application. Una vulnerabilidad de tipo cross-site request forgery (CSRF) en el archivo /controller/pay.class.php de YzmCMS versión v5.5, permite a atacantes acceder a componentes confidenciales de la aplicación • https://github.com/yzmcms/yzmcms/issues/43 • CWE-352: Cross-Site Request Forgery (CSRF) •

CVSS: 7.5EPSS: 0%CPEs: 1EXPL: 1

YzmCMS v5.5 contains a server-side request forgery (SSRF) in the grab_image() function. YzmCMS versión v5.5, contiene una vulnerabilidad de tipo server-side request forgery (SSRF) en la función grab_image() • https://github.com/yzmcms/yzmcms/issues/44 • CWE-918: Server-Side Request Forgery (SSRF) •

CVSS: 6.1EPSS: 0%CPEs: 1EXPL: 1

In YzmCMS v5.5 the member contribution function in the editor contains a cross-site scripting (XSS) vulnerability. En YzmCMS versión v5.5, la función member contribution en el editor contiene una vulnerabilidad de tipo Cross-site Scripting (XSS) • https://github.com/yzmcms/yzmcms/issues/42 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •