CVE-2023-3839 – DedeBIZ sys_sql_query.php sql injection
https://notcve.org/view.php?id=CVE-2023-3839
A vulnerability, which was classified as problematic, has been found in DedeBIZ 6.2.10. Affected by this issue is some unknown functionality of the file /admin/sys_sql_query.php. The manipulation of the argument sqlquery leads to sql injection. The attack may be launched remotely. The complexity of an attack is rather high. • https://github.com/TXPH/CVE/blob/main/sqli-report.pdf https://vuldb.com/?ctiid.235190 https://vuldb.com/?id.235190 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •
CVE-2023-3838 – DedeBIZ vote_edit.php cross site scripting
https://notcve.org/view.php?id=CVE-2023-3838
A vulnerability classified as problematic was found in DedeBIZ 6.2.10. Affected by this vulnerability is an unknown functionality of the file /admin/vote_edit.php. The manipulation leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. • https://github.com/TXPH/CVE/blob/main/xss-report2.pdf https://vuldb.com/?ctiid.235189 https://vuldb.com/?id.235189 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2023-3837 – DedeBIZ sys_sql_query.php cross site scripting
https://notcve.org/view.php?id=CVE-2023-3837
A vulnerability classified as problematic has been found in DedeBIZ 6.2.10. Affected is an unknown function of the file /admin/sys_sql_query.php. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. • https://github.com/TXPH/CVE/blob/main/xss-report.pdf https://vuldb.com/?ctiid.235188 https://vuldb.com/?id.235188 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •