Page 3 of 27 results (0.005 seconds)

CVSS: 6.1EPSS: 0%CPEs: 1EXPL: 2

XSS exists in WUZHI CMS 4.1.0 via index.php?m=content&f=postinfo&v=listing&set_iframe=[XSS] to coreframe/app/content/postinfo.php. Existe Cross-Site Scripting (XSS) en WUZHI CMS 4.1.0 mediante index.php?m=contentf=postinfov=listingset_iframe=[XSS] en coreframe/app/content/postinfo.php. • https://gist.github.com/redeye5/470708bd27ed115b29d0434255b9f7a0 https://github.com/wuzhicms/wuzhicms/issues/170 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 6.1EPSS: 0%CPEs: 1EXPL: 2

XSS exists in WUZHI CMS 4.1.0 via index.php?m=message&f=message&v=add&username=[XSS] to coreframe/app/message/message.php. Existe Cross-Site Scripting (XSS) en WUZHI CMS 4.1.0 mediante index.php?m=messagef=messagev=addusername=[XSS] en coreframe/app/message/message.php. • https://gist.github.com/redeye5/57ccafea7263efec67c82b0503c72480 https://github.com/wuzhicms/wuzhicms/issues/172 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 4.8EPSS: 0%CPEs: 1EXPL: 1

An issue was discovered in WUZHI CMS 4.1.0. There is stored XSS in index.php?m=core&f=index via an ontoggle attribute to details/open/ within a second input field. Se ha descubierto un problema en WUZHI CMS 4.1.0. Hay Cross-Site Scripting (XSS) persistente en index.php? • https://github.com/wuzhicms/wuzhicms/issues/158 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 8.8EPSS: 0%CPEs: 1EXPL: 1

An issue was discovered in WUZHI CMS 4.1.0. There is a CSRF vulnerability that can change the super administrator's username via index.php?m=member&f=index&v=edit&uid=1. Se ha descubierto un problema en WUZHI CMS 4.1.0. Hay una vulnerabilidad CSRF que puede cambiar el nombre de usuario del superadministrador mediante index.php? • https://github.com/wuzhicms/wuzhicms/issues/156 • CWE-352: Cross-Site Request Forgery (CSRF) •

CVSS: 8.8EPSS: 0%CPEs: 1EXPL: 1

An issue was discovered in WUZHI CMS 4.1.0. There is a CSRF vulnerability that can change the super administrator's password via index.php?m=core&f=panel&v=edit_info. Se ha descubierto un problema en WUZHI CMS 4.1.0. Hay una vulnerabilidad CSRF que puede cambiar la contraseña del superadministrador mediante index.php? • https://github.com/wuzhicms/wuzhicms/issues/156 • CWE-352: Cross-Site Request Forgery (CSRF) •