Show filters
3 Total Results
Displaying 1-3 of 3
Sort by:
Attacker Value
Unknown

CVE-2020-20131

Disclosure Date: September 29, 2021 (last updated February 23, 2025)
LaraCMS v1.0.1 contains a stored cross-site scripting (XSS) vulnerability which allows atackers to execute arbitrary web scripts or HTML via a crafted payload in the page management module.
Attacker Value
Unknown

CVE-2020-20129

Disclosure Date: September 29, 2021 (last updated February 23, 2025)
LaraCMS v1.0.1 contains a stored cross-site scripting (XSS) vulnerability which allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the content editor.
Attacker Value
Unknown

CVE-2020-20128

Disclosure Date: September 29, 2021 (last updated February 23, 2025)
LaraCMS v1.0.1 transmits sensitive information in cleartext which can be intercepted by attackers.