Show filters
13 Total Results
Displaying 11-13 of 13
Sort by:
Attacker Value
Unknown
CVE-2023-24369
Disclosure Date: February 17, 2023 (last updated October 08, 2023)
A cross-site scripting (XSS) vulnerability in UJCMS v4.1.3 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the URL parameter under the Add New Articles function.
0
Attacker Value
Unknown
CVE-2022-28090
Disclosure Date: May 04, 2022 (last updated October 07, 2023)
Jspxcms v10.2.0 allows attackers to execute a Server-Side Request Forgery (SSRF) via /cmscp/ext/collect/fetch_url.do?url=.
0
Attacker Value
Unknown
CVE-2022-23329
Disclosure Date: February 04, 2022 (last updated February 23, 2025)
A vulnerability in ${"freemarker.template.utility.Execute"?new() of UJCMS Jspxcms v10.2.0 allows attackers to execute arbitrary commands via uploading malicious files.
0