Show filters
5 Total Results
Displaying 1-5 of 5
Sort by:
Attacker Value
Unknown
CVE-2022-23383
Disclosure Date: March 10, 2022 (last updated February 23, 2025)
YzmCMS v6.3 is affected by broken access control. Without login, unauthorized access to the user's personal home page can be realized. It is necessary to judge the user's login status before accessing the personal home page, but the vulnerability can access other users' home pages through the non login status because real authentication is not carried out.
0
Attacker Value
Unknown
CVE-2022-23384
Disclosure Date: February 15, 2022 (last updated February 23, 2025)
YzmCMS v6.3 is affected by Cross Site Request Forgery (CSRF) in /admin.add
0
Attacker Value
Unknown
CVE-2022-23889
Disclosure Date: January 28, 2022 (last updated February 23, 2025)
The comment function in YzmCMS v6.3 was discovered as being able to be operated concurrently, allowing attackers to create an unusually large number of comments.
0
Attacker Value
Unknown
CVE-2022-23888
Disclosure Date: January 28, 2022 (last updated February 23, 2025)
YzmCMS v6.3 was discovered to contain a Cross-Site Request Forgey (CSRF) via the component /yzmcms/comment/index/init.html.
0
Attacker Value
Unknown
CVE-2022-23887
Disclosure Date: January 28, 2022 (last updated February 23, 2025)
YzmCMS v6.3 was discovered to contain a Cross-Site Request Forgery (CSRF) which allows attackers to arbitrarily delete user accounts via /admin/admin_manage/delete.
0