RSS   Vulnerabilities for 'Symphony cms'   RSS

2020-08-11
 
CVE-2020-15071

CWE-79
 

 
content/content.blueprintsevents.php in Symphony CMS 3.0.0 allows XSS via fields['name'] to appendSubheading.

 
2017-05-10
 
CVE-2017-8876

 

 
Symphony 2 2.6.11 has XSS in the meta[navigation_group] parameter to content/content.blueprintssections.php.

 
2017-04-11
 
CVE-2017-7694

 

 
Remote Code Execution vulnerability in symphony/content/content.blueprintsdatasources.php in Symphony CMS through 2.6.11 allows remote attackers to execute code and get a webshell from the back-end. The attacker must be authenticated and enter PHP code in the datasource editor or event editor.

 
2017-03-26
 
CVE-2017-6067

CWE-79
 

 
Symphony 2.6.9 has XSS in publish/notes/edit/##/saved/ via the bottom form field.

 
 
CVE-2017-6006

 

 
Symphony 2.6.11 has XSS in publish/articles/new/ via the Body field.

 

 >>> Vendor: Getsymphony 2 Products
Symphony
Symphony cms


Copyright 2024, cxsecurity.com

 

Back to Top