CVE-2020-19951
https://notcve.org/view.php?id=CVE-2020-19951
23 Sep 2021 — A cross-site request forgery (CSRF) in /controller/pay.class.php of YzmCMS v5.5 allows attackers to access sensitive components of the application. Una vulnerabilidad de tipo cross-site request forgery (CSRF) en el archivo /controller/pay.class.php de YzmCMS versión v5.5, permite a atacantes acceder a componentes confidenciales de la aplicación • https://github.com/yzmcms/yzmcms/issues/43 • CWE-352: Cross-Site Request Forgery (CSRF) •
CVE-2020-20341
https://notcve.org/view.php?id=CVE-2020-20341
01 Sep 2021 — YzmCMS v5.5 contains a server-side request forgery (SSRF) in the grab_image() function. YzmCMS versión v5.5, contiene una vulnerabilidad de tipo server-side request forgery (SSRF) en la función grab_image() • https://github.com/yzmcms/yzmcms/issues/44 • CWE-918: Server-Side Request Forgery (SSRF) •
CVE-2020-22394
https://notcve.org/view.php?id=CVE-2020-22394
19 Nov 2020 — In YzmCMS v5.5 the member contribution function in the editor contains a cross-site scripting (XSS) vulnerability. En YzmCMS versión v5.5, la función member contribution en el editor contiene una vulnerabilidad de tipo Cross-site Scripting (XSS) • https://github.com/yzmcms/yzmcms/issues/42 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •