CVE-2018-10313 – WUZHI CMS 4.1.0 - 'form[qq_10]' Cross-Site Scripting
https://notcve.org/view.php?id=CVE-2018-10313
WUZHI CMS 4.1.0 allows persistent XSS via the form%5Bqq_10%5D parameter to the /index.php?m=member&f=index&v=profile&set_iframe=1 URI. WUZHI CMS 4.1.0 permite Cross-Site Scripting (XSS) persistente mediante el parámetro form%5Bqq_10%5D en el URI /index.php?m=memberf=indexv=profileset_iframe=1. Wuzhi CMS version 4.1.0 suffers from multiple cross site scripting vulnerabilities. • https://www.exploit-db.com/exploits/44617 https://github.com/wuzhicms/wuzhicms/issues/133 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2018-10312 – WUZHI CMS 4.1.0 - Cross-Site Request Forgery
https://notcve.org/view.php?id=CVE-2018-10312
index.php?m=member&v=pw_reset in WUZHI CMS 4.1.0 allows CSRF to change the password of a common member. index.php?m=memberv=pw_reset en WUZHI CMS 4.1.0 permite Cross-Site Request Forgery (CSRF) para cambiar la contraseña de un miembro común. Wuzhi CMS version 4.1.0 suffers from a cross site request forgery vulnerability. • https://www.exploit-db.com/exploits/44504 https://github.com/wuzhicms/wuzhicms/issues/132 • CWE-352: Cross-Site Request Forgery (CSRF) •
CVE-2018-10311 – WUZHI CMS 4.1.0 - 'tag[pinyin]' Cross-Site Scripting
https://notcve.org/view.php?id=CVE-2018-10311
A vulnerability was discovered in WUZHI CMS 4.1.0. There is persistent XSS that allows remote attackers to inject arbitrary web script or HTML via the tag[pinyin] parameter to the /index.php?m=tags&f=index&v=add URI. Se ha descubierto una vulnerabilidad en WUZHI CMS 4.1.0. Hay Cross-Site Scripting (XSS) persistente que permite que atacantes remotos inyecten scripts web o HTML arbitrarios mediante el parámetro tag[pinyin] en el URI /index.php? • https://www.exploit-db.com/exploits/44618 https://github.com/wuzhicms/wuzhicms/issues/131 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2018-10248
https://notcve.org/view.php?id=CVE-2018-10248
An issue was discovered in WUZHI CMS 4.1.0. There is a CSRF vulnerability that can delete any article via index.php?m=content&f=content&v=recycle_delete. Se ha descubierto un problema en WUZHI CMS 4.1.0. Hay una vulnerabilidad de Cross-Site Request Forgery (CSRF) que puede eliminar cualquier artículo mediante index.php? • https://github.com/wuzhicms/wuzhicms/issues/130 • CWE-352: Cross-Site Request Forgery (CSRF) •
CVE-2018-10221
https://notcve.org/view.php?id=CVE-2018-10221
An issue was discovered in WUZHI CMS V4.1.0. There is a persistent XSS vulnerability that can steal the administrator cookies via the tag[tag] parameter to the index.php?m=tags&f=index&v=add&&_su=wuzhicms URI. After a website editor (whose privilege is lower than the administrator) logs in, he can add a new TAGS with the XSS payload. Se ha descubierto un problema en WUZHI CMS V4.1.0. • https://github.com/wuzhicms/wuzhicms/issues/129 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •