RSS   Vulnerabilities for 'Wuzhi cms'   RSS

2018-05-29
 
CVE-2018-11549

CWE-79
 

 
An issue was discovered in WUZHI CMS 4.1.0 There is a Stored XSS Vulnerability in "Account Settings -> Member Centre -> Chinese information -> Ordinary member" via a QQ number, as demonstrated by a form[qq_10]= substring.

 
 
CVE-2018-11528

CWE-89
 

 
WUZHI CMS 4.1.0 has SQL Injection via an api/sms_check.php?param= URI.

 
2018-05-26
 
CVE-2018-11493

CWE-352
 

 
An issue was discovered in WUZHI CMS 4.1.0. There is a CSRF vulnerability that can add a friendship link via index.php?m=link&f=index&v=add.

 
2018-04-26
 
CVE-2018-10391

CWE-79
 

 
An issue was discovered in WUZHI CMS 4.1.0. There is XSS via the email parameter to the index.php?m=member&v=register URI.

 
2018-04-25
 
CVE-2018-10368

CWE-79
 

 
An issue was discovered in WUZHI CMS 4.1.0. The "Extension Module -> System Announcement" feature has Stored XSS via an announcement.

 
 
CVE-2018-10367

CWE-79
 

 
An issue was discovered in WUZHI CMS 4.1.0. The content-management feature has Stored XSS via the title or content section.

 
2018-04-23
 
CVE-2018-10313

CWE-79
 

 
WUZHI CMS 4.1.0 allows persistent XSS via the form%5Bqq_10%5D parameter to the /index.php?m=member&f=index&v=profile&set_iframe=1 URI.

 
 
CVE-2018-10312

CWE-352
 

 
index.php?m=member&v=pw_reset in WUZHI CMS 4.1.0 allows CSRF to change the password of a common member.

 
 
CVE-2018-10311

CWE-79
 

 
A vulnerability was discovered in WUZHI CMS 4.1.0. There is persistent XSS that allows remote attackers to inject arbitrary web script or HTML via the tag[pinyin] parameter to the /index.php?m=tags&f=index&v=add URI.

 
2018-04-20
 
CVE-2018-10248

CWE-352
 

 
An issue was discovered in WUZHI CMS 4.1.0. There is a CSRF vulnerability that can delete any article via index.php?m=content&f=content&v=recycle_delete.

 


Copyright 2018, cxsecurity.com

 

Back to Top