CVE-2019-14518
https://notcve.org/view.php?id=CVE-2019-14518
Evolution CMS 2.0.x allows XSS via a description and new category location in a template. NOTE: the vendor states that the behavior is consistent with the "access policy in the administration panel. ** EN DISPUTA ** Evolution CMS 2.0.x permite XSS a través de una descripción y una nueva ubicación de categoría en una plantilla. NOTA: el proveedor indica que el comportamiento es consistente con la "política de acceso en el panel de administración" • https://github.com/evolution-cms/evolution/issues/1041 https://github.com/evolution-cms/evolution/issues/1042 https://github.com/evolution-cms/evolution/issues/1043 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2018-16637
https://notcve.org/view.php?id=CVE-2018-16637
Evolution CMS 1.4.x allows XSS via the page weblink title parameter to the manager/ URI. Evolution CMS 1.4.x permite Cross-Site Scripting (XSS) mediante el parámetro title en el weblink de la página en el URI manager/. • https://github.com/security-breachlock/CVE-2018-16637/blob/master/evolution_xss_stored.pdf • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2018-16638
https://notcve.org/view.php?id=CVE-2018-16638
Evolution CMS 1.4.x allows XSS via the manager/ search parameter. Evolution CMS 1.4.x permite Cross-Site Scripting (XSS) mediante el parámetro search en manager/. • https://github.com/security-breachlock/CVE-2018-16638/blob/master/evolution_xss_reflected.pdf • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •