Show filters
5 Total Results
Displaying 1-5 of 5
Sort by:
Attacker Value
Unknown

CVE-2022-23383

Disclosure Date: March 10, 2022 (last updated February 23, 2025)
YzmCMS v6.3 is affected by broken access control. Without login, unauthorized access to the user's personal home page can be realized. It is necessary to judge the user's login status before accessing the personal home page, but the vulnerability can access other users' home pages through the non login status because real authentication is not carried out.
Attacker Value
Unknown

CVE-2022-23384

Disclosure Date: February 15, 2022 (last updated February 23, 2025)
YzmCMS v6.3 is affected by Cross Site Request Forgery (CSRF) in /admin.add
Attacker Value
Unknown

CVE-2022-23889

Disclosure Date: January 28, 2022 (last updated February 23, 2025)
The comment function in YzmCMS v6.3 was discovered as being able to be operated concurrently, allowing attackers to create an unusually large number of comments.
Attacker Value
Unknown

CVE-2022-23888

Disclosure Date: January 28, 2022 (last updated February 23, 2025)
YzmCMS v6.3 was discovered to contain a Cross-Site Request Forgey (CSRF) via the component /yzmcms/comment/index/init.html.
Attacker Value
Unknown

CVE-2022-23887

Disclosure Date: January 28, 2022 (last updated February 23, 2025)
YzmCMS v6.3 was discovered to contain a Cross-Site Request Forgery (CSRF) which allows attackers to arbitrarily delete user accounts via /admin/admin_manage/delete.