RSS   Vulnerabilities for 'Tpcms'   RSS

2022-04-04
 
CVE-2022-27441

CWE-79
 

 
A stored cross-site scripting (XSS) vulnerability in TPCMS v3.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Phone text box.

 
 
CVE-2022-27442

CWE-532
 

 
TPCMS v3.2 allows attackers to access the ThinkPHP log directory and obtain sensitive information such as the administrator's user name and password.

 


Copyright 2024, cxsecurity.com

 

Back to Top