Note:
This project will be discontinued after December 13, 2021. [more]
Product:
News_script_php_pro
(Newsscriptphp)Repositories |
Unknown: This might be proprietary software. |
#Vulnerabilities | 4 |
Date | Id | Summary | Products | Score | Patch | Annotated |
---|---|---|---|---|---|---|
2020-11-24 | CVE-2020-25472 | SimplePHPscripts News Script PHP Pro 2.3 is affected by a Cross Site Request Forgery (CSRF) vulnerability, which allows attackers to add new users. | News_script_php_pro | 6.5 | ||
2020-11-24 | CVE-2020-25473 | SimplePHPscripts News Script PHP Pro 2.3 does not properly set the HttpOnly Flag from Session Cookies. | News_script_php_pro | 6.5 | ||
2020-11-24 | CVE-2020-25474 | SimplePHPscripts News Script PHP Pro 2.3 is affected by a Cross Site Scripting (XSS) vulnerability via the editor_name parameter. | News_script_php_pro | 6.1 | ||
2020-11-24 | CVE-2020-25475 | SimplePHPscripts News Script PHP Pro 2.3 is affected by a SQL Injection via the id parameter in an editNews action. | News_script_php_pro | 9.8 |