Show filters
17 Total Results
Displaying 1-10 of 17
Sort by:
Attacker Value
Unknown
CVE-2025-1557
Disclosure Date: February 22, 2025 (last updated February 23, 2025)
A vulnerability, which was classified as problematic, was found in OFCMS 1.1.3. Affected is an unknown function. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
0
Attacker Value
Unknown
CVE-2024-9411
Disclosure Date: October 01, 2024 (last updated October 02, 2024)
A vulnerability classified as problematic has been found in OFCMS 1.1.2. This affects the function add of the file /admin/system/dict/add.json?sqlid=system.dict.save. The manipulation of the argument dict_value leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
0
Attacker Value
Unknown
CVE-2023-51807
Disclosure Date: January 16, 2024 (last updated January 24, 2024)
Cross Site Scripting vulnerability in OFCMS v.1.14 allows a remote attacker to obtain sensitive information via a crafted payload to the title addition component.
0
Attacker Value
Unknown
CVE-2023-24760
Disclosure Date: March 16, 2023 (last updated October 08, 2023)
An issue found in Ofcms v.1.1.4 allows a remote attacker to to escalate privileges via the respwd method in SysUserController.
0
Attacker Value
Unknown
CVE-2022-29653
Disclosure Date: June 02, 2022 (last updated October 07, 2023)
OFCMS v1.1.4 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /admin/comn/service/update.json.
0
Attacker Value
Unknown
CVE-2022-27961
Disclosure Date: April 10, 2022 (last updated October 07, 2023)
A cross-site scripting (XSS) vulnerability at /ofcms/company-c-47 in OFCMS v1.1.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Comment text box.
0
Attacker Value
Unknown
CVE-2022-27960
Disclosure Date: April 10, 2022 (last updated October 07, 2023)
Insecure permissions configured in the user_id parameter at SysUserController.java of OFCMS v1.1.4 allows attackers to access and arbitrarily modify users' personal information.
0
Attacker Value
Unknown
CVE-2019-9608
Disclosure Date: March 06, 2019 (last updated November 27, 2024)
An issue was discovered in OFCMS before 1.1.3. Remote attackers can execute arbitrary code because blocking of .jsp and .jspx files does not consider (for example) file.jsp::$DATA to the admin/ueditor/uploadImage URI.
0
Attacker Value
Unknown
CVE-2019-9614
Disclosure Date: March 06, 2019 (last updated November 27, 2024)
An issue was discovered in OFCMS before 1.1.3. A command execution vulnerability exists via a template file with '<#assign ex="freemarker.template.utility.Execute"?new()> ${ ex("' followed by the command.
0
Attacker Value
Unknown
CVE-2019-9610
Disclosure Date: March 06, 2019 (last updated November 27, 2024)
An issue was discovered in OFCMS before 1.1.3. It has admin/cms/template/getTemplates.html?res_path=res&up_dir=../ directory traversal, related to the getTemplates function in TemplateController.java.
0