Filtered by vendor Yxcms
Subscribe
Search
Total
2 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2018-8761 | 1 Yxcms | 1 Yxcms | 2019-10-03 | 5.0 MEDIUM | 7.5 HIGH |
| protected\apps\member\controller\shopcarController.php in Yxcms building system (compatible cell phone) v1.4.7 has a logic flaw allowing attackers to modify a price, before form submission, by observing data in a packet capture. | |||||
| CVE-2018-19404 | 1 Yxcms | 1 Yxcms | 2018-12-19 | 6.5 MEDIUM | 7.2 HIGH |
| In YXcms 1.4.7, protected/apps/appmanage/controller/indexController.php allow remote authenticated Administrators to execute any PHP code by creating a ZIP archive containing a config.php file, hosting the .zip file at an external URL, and visiting index.php?r=appmanage/index/onlineinstall&url= followed by that URL. This is related to the onlineinstall and import functions. | |||||
