CVE-2023-48930
https://notcve.org/view.php?id=CVE-2023-48930
xinhu xinhuoa 2.2.1 contains a File upload vulnerability. xinhu xinhuoa 2.2.1 contiene una vulnerabilidad de carga de archivos. • https://gist.github.com/Maverickfir/b8113bdb51ec66e454ffa5b50674c446 https://github.com/Maverickfir/Vulnerability-recurrence/blob/main/xinhuOA.md https://github.com/Maverickfir/xinhuOA2.2.1 • CWE-434: Unrestricted Upload of File with Dangerous Type •
CVE-2022-45041
https://notcve.org/view.php?id=CVE-2022-45041
SQL Injection exits in xinhu < 2.5.0 La inyección SQL sale en xinhu < 2.5.0 • https://github.com/N1k0la-T/somefiles/blob/main/sqli.py https://github.com/N1k0la-T/vulnerability/issues/1 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •
CVE-2020-35388
https://notcve.org/view.php?id=CVE-2020-35388
rainrocka xinhu 2.1.9 allows remote attackers to obtain sensitive information via an index.php?a=gettotal request in which the ajaxbool value is manipulated to be true. rainrocka xinhu versión 2.1.9, permite a atacantes remotos obtener información confidencial por medio de una petición a index.php?a=gettotal en la que el valor de ajaxbool es manipulado para que sea verdadero • https://github.com/xuechengen/xinhu-oa/blob/main/README.md •