Show filters
9 Total Results
Displaying 1-9 of 9
Sort by:
Attacker Value
Unknown

CVE-2023-2057

Disclosure Date: April 14, 2023 (last updated October 08, 2023)
A vulnerability was found in EyouCms 1.5.4. It has been classified as problematic. Affected is an unknown function of the file login.php?m=admin&c=Arctype&a=edit of the component New Picture Handler. The manipulation of the argument litpic_loca leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-225942 is the identifier assigned to this vulnerability.
Attacker Value
Unknown

CVE-2021-39428

Disclosure Date: December 15, 2022 (last updated October 08, 2023)
Cross Site Scripting (XSS) vulnerability in Users.php in eyoucms 1.5.4 allows remote attackers to run arbitrary code and gain escalated privilege via the filename for edit_users_head_pic.
Attacker Value
Unknown

CVE-2022-26273

Disclosure Date: March 28, 2022 (last updated October 07, 2023)
EyouCMS v1.5.4 was discovered to lack parameter filtering in \user\controller\shop.php, leading to payment logic vulnerabilities.
Attacker Value
Unknown

CVE-2021-42194

Disclosure Date: March 20, 2022 (last updated February 23, 2025)
The wechat_return function in /controller/Index.php of EyouCms V1.5.4-UTF8-SP3 passes the user's input directly into the simplexml_ load_ String function, which itself does not prohibit external entities, triggering a XML external entity (XXE) injection vulnerability.
Attacker Value
Unknown

CVE-2021-39501

Disclosure Date: September 07, 2021 (last updated February 23, 2025)
EyouCMS 1.5.4 is vulnerable to Open Redirect. An attacker can redirect a user to a malicious url via the Logout function.
Attacker Value
Unknown

CVE-2021-39500

Disclosure Date: September 07, 2021 (last updated February 23, 2025)
Eyoucms 1.5.4 is vulnerable to Directory Traversal. Due to a lack of input data sanitizaton in param tpldir, filename, type, nid an attacker can inject "../" to escape and write file to writeable directories.
Attacker Value
Unknown

CVE-2021-39497

Disclosure Date: September 07, 2021 (last updated February 23, 2025)
eyoucms 1.5.4 lacks sanitization of input data, allowing an attacker to inject a url to trigger blind SSRF via the saveRemote() function.
Attacker Value
Unknown

CVE-2021-39499

Disclosure Date: September 07, 2021 (last updated February 23, 2025)
A Cross-site scripting (XSS) vulnerability in Users in Qiong ICP EyouCMS 1.5.4 allows remote attackers to inject arbitrary web script or HTML via the `title` parameter in bind_email function.
Attacker Value
Unknown

CVE-2021-39496

Disclosure Date: September 07, 2021 (last updated February 23, 2025)
Eyoucms 1.5.4 lacks sanitization of input data, allowing an attacker to inject malicious code into `filename` param to trigger Reflected XSS.