Vulnerabilities (CVE)

Filtered by vendor Xiaocms Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2019-6127 1 Xiaocms 1 Xiaocms 2019-01-23 6.5 MEDIUM 7.2 HIGH
An issue was discovered in XiaoCms 20141229. It allows admin/index.php?c=database table[] SQL injection. This can be used for PHP code execution via "INTO OUTFILE" with a .php filename.
CVE-2018-19192 1 Xiaocms 1 Xiaocms 2018-12-13 6.8 MEDIUM 8.8 HIGH
An issue was discovered in XiaoCms 20141229. admin/index.php?c=content&a=add&catid=3 has CSRF, as demonstrated by entering news via the data[content] parameter.
CVE-2018-14331 1 Xiaocms 1 Xiaocms X1 2018-09-17 6.8 MEDIUM 8.8 HIGH
An issue was discovered in XiaoCms X1 v20140305. There is a CSRF vulnerability to change the administrator account password via admin/index.php?c=index&a=my.