Note:
This project will be discontinued after December 13, 2021. [more]
Product:
Ed01\-Cms
(Ed01\-Cms_project)Repositories |
Unknown: This might be proprietary software. |
#Vulnerabilities | 6 |
Date | Id | Summary | Products | Score | Patch | Annotated |
---|---|---|---|---|---|---|
2024-04-25 | CVE-2024-30890 | Cross Site Scripting vulnerability in ED01-CMS v.1.0 allows an attacker to obtain sensitive information via the categories.php component. | Ed01\-Cms | N/A | ||
2021-11-03 | CVE-2020-18259 | ED01-CMS v1.0 was discovered to contain a reflective cross-site scripting (XSS) vulnerability in the component sposts.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload inserted into the Post title or Post content fields. | Ed01\-Cms | 6.1 | ||
2021-11-03 | CVE-2020-18261 | An arbitrary file upload vulnerability in the image upload function of ED01-CMS v1.0 allows attackers to execute arbitrary commands. | Ed01\-Cms | 9.8 | ||
2021-11-03 | CVE-2020-18262 | ED01-CMS v1.0 was discovered to contain a SQL injection in the component cposts.php via the cid parameter. | Ed01\-Cms | 9.8 | ||
2022-04-26 | CVE-2022-28524 | ED01-CMS v20180505 was discovered to contain a SQL injection vulnerability via the component post.php. | Ed01\-Cms | 9.8 | ||
2022-04-26 | CVE-2022-28525 | ED01-CMS v20180505 was discovered to contain an arbitrary file upload vulnerability via /admin/users.php?source=edit_user&id=1. | Ed01\-Cms | 8.8 |