Show filters
5 Total Results
Displaying 1-5 of 5
Sort by:
Attacker Value
Unknown
CVE-2023-51807
Disclosure Date: January 16, 2024 (last updated January 24, 2024)
Cross Site Scripting vulnerability in OFCMS v.1.14 allows a remote attacker to obtain sensitive information via a crafted payload to the title addition component.
0
Attacker Value
Unknown
CVE-2023-24760
Disclosure Date: March 16, 2023 (last updated October 08, 2023)
An issue found in Ofcms v.1.1.4 allows a remote attacker to to escalate privileges via the respwd method in SysUserController.
0
Attacker Value
Unknown
CVE-2022-29653
Disclosure Date: June 02, 2022 (last updated February 23, 2025)
OFCMS v1.1.4 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /admin/comn/service/update.json.
0
Attacker Value
Unknown
CVE-2022-27961
Disclosure Date: April 10, 2022 (last updated February 23, 2025)
A cross-site scripting (XSS) vulnerability at /ofcms/company-c-47 in OFCMS v1.1.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Comment text box.
0
Attacker Value
Unknown
CVE-2022-27960
Disclosure Date: April 10, 2022 (last updated February 23, 2025)
Insecure permissions configured in the user_id parameter at SysUserController.java of OFCMS v1.1.4 allows attackers to access and arbitrarily modify users' personal information.
0