Show filters
3 Total Results
Displaying 1-3 of 3
Sort by:
Attacker Value
Unknown

CVE-2020-18701

Disclosure Date: August 16, 2021 (last updated February 23, 2025)
Incorrect Access Control in Lin-CMS-Flask v0.1.1 allows remote attackers to obtain sensitive information and/or gain privileges due to the application not invalidating a user's authentication token upon logout, which allows for replaying packets.
Attacker Value
Unknown

CVE-2020-18699

Disclosure Date: August 16, 2021 (last updated February 23, 2025)
Cross Site Scripting (XSS) in Lin-CMS-Flask v0.1.1 allows remote attackers to execute arbitrary code by entering scripts in the the 'Username' parameter of the in component 'app/api/cms/user.py'.
Attacker Value
Unknown

CVE-2020-18698

Disclosure Date: August 16, 2021 (last updated February 23, 2025)
Improper Authentication in Lin-CMS-Flask v0.1.1 allows remote attackers to launch brute force login attempts without restriction via the 'login' function in the component 'app/api/cms/user.py'.