Show filters
25 Total Results
Displaying 11-20 of 25
Sort by:
Attacker Value
Unknown

CVE-2024-22603

Disclosure Date: January 18, 2024 (last updated January 24, 2024)
FlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerability via /system/links/add_link
Attacker Value
Unknown

CVE-2024-22601

Disclosure Date: January 18, 2024 (last updated January 24, 2024)
FlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerability via /system/score/scorerule_save
Attacker Value
Unknown

CVE-2024-22699

Disclosure Date: January 18, 2024 (last updated January 24, 2024)
FlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerability via /system/admin/update_group_save.
Attacker Value
Unknown

CVE-2024-22593

Disclosure Date: January 18, 2024 (last updated January 21, 2024)
FlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerability via /system/admin/add_group_save
Attacker Value
Unknown

CVE-2024-22592

Disclosure Date: January 18, 2024 (last updated January 21, 2024)
FlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerability via /system/user/group_update
Attacker Value
Unknown

CVE-2024-22591

Disclosure Date: January 18, 2024 (last updated January 21, 2024)
FlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerability via /system/user/group_save.
Attacker Value
Unknown

CVE-2024-22568

Disclosure Date: January 18, 2024 (last updated January 21, 2024)
FlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerability via /system/score/del.
Attacker Value
Unknown

CVE-2024-22549

Disclosure Date: January 18, 2024 (last updated January 21, 2024)
FlyCms 1.0 is vulnerable to Cross Site Scripting (XSS) in the email settings of the website settings section.
Attacker Value
Unknown

CVE-2024-22548

Disclosure Date: January 18, 2024 (last updated January 21, 2024)
FlyCms 1.0 is vulnerable to Cross Site Scripting (XSS) in the system website settings website name section.
Attacker Value
Unknown

CVE-2023-52074

Disclosure Date: January 08, 2024 (last updated January 12, 2024)
FlyCms v1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component system/site/webconfig_updagte.