Show filters
12 Total Results
Displaying 1-10 of 12
Sort by:
Attacker Value
Unknown

CVE-2020-36828

Disclosure Date: March 31, 2024 (last updated February 26, 2025)
A vulnerability was found in DiscuzX up to 3.4-20200818. It has been classified as problematic. Affected is the function show_next_step of the file upload/install/include/install_function.php. The manipulation of the argument uchidden leads to cross site scripting. It is possible to launch the attack remotely. Upgrading to version 3.4-20210119 is able to address this issue. The name of the patch is 4a9673624f46f7609486778ded9653733020c567. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-258612.
0
Attacker Value
Unknown

CVE-2022-45543

Disclosure Date: February 15, 2023 (last updated February 24, 2025)
Cross site scripting (XSS) vulnerability in DiscuzX 3.4 allows attackers to execute arbitrary code via the datetline, title, tpp, or username parameters via the audit search.
Attacker Value
Unknown

CVE-2018-20424

Disclosure Date: December 24, 2018 (last updated November 27, 2024)
Discuz! DiscuzX 3.4, when WeChat login is enabled, allows remote attackers to delete the common_member_wechatmp data structure via an ac=unbindmp request to plugin.php.
0
Attacker Value
Unknown

CVE-2018-20423

Disclosure Date: December 24, 2018 (last updated November 27, 2024)
Discuz! DiscuzX 3.4, when WeChat login is enabled, allows remote attackers to bypass a "disabled registration" setting by adding a non-existing wxopenid value to the plugin.php ac=wxregister query string.
0
Attacker Value
Unknown

CVE-2018-20422

Disclosure Date: December 24, 2018 (last updated November 27, 2024)
Discuz! DiscuzX 3.4, when WeChat login is enabled, allows remote attackers to bypass authentication by leveraging a non-empty #wechat#common_member_wechatmp to gain login access to an account via a plugin.php ac=wxregister request (the attacker does not have control over which account will be accessed).
0
Attacker Value
Unknown

CVE-2018-10297

Disclosure Date: April 22, 2018 (last updated November 26, 2024)
Discuz! DiscuzX through X3.4 has stored XSS via the portal.php?mod=portalcp&ac=article URI, related to mishandling of IMG elements associated with remote images.
0
Attacker Value
Unknown

CVE-2018-10298

Disclosure Date: April 22, 2018 (last updated November 26, 2024)
Discuz! DiscuzX through X3.4 has reflected XSS via forum.php?mod=post&action=newthread because data/template/1_diy_portal_view.tpl.php does not restrict the content.
0
Attacker Value
Unknown

CVE-2018-5375

Disclosure Date: January 12, 2018 (last updated November 26, 2024)
Discuz! DiscuzX X3.4 has XSS via the include\spacecp\spacecp_space.php appid parameter in a delete action.
0
Attacker Value
Unknown

CVE-2018-5377

Disclosure Date: January 12, 2018 (last updated November 26, 2024)
Discuz! DiscuzX X3.4 allows remote attackers to bypass intended access restrictions via the archiver\index.php action parameter.
0
Attacker Value
Unknown

CVE-2018-5376

Disclosure Date: January 12, 2018 (last updated November 26, 2024)
Discuz! DiscuzX X3.4 has XSS via the include\spacecp\spacecp_upload.php op parameter.