Show filters
15 Total Results
Displaying 1-10 of 15
Sort by:
Attacker Value
Unknown

CVE-2023-51807

Disclosure Date: January 16, 2024 (last updated January 24, 2024)
Cross Site Scripting vulnerability in OFCMS v.1.14 allows a remote attacker to obtain sensitive information via a crafted payload to the title addition component.
Attacker Value
Unknown

CVE-2023-24760

Disclosure Date: March 16, 2023 (last updated October 08, 2023)
An issue found in Ofcms v.1.1.4 allows a remote attacker to to escalate privileges via the respwd method in SysUserController.
Attacker Value
Unknown

CVE-2022-29653

Disclosure Date: June 02, 2022 (last updated February 23, 2025)
OFCMS v1.1.4 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /admin/comn/service/update.json.
Attacker Value
Unknown

CVE-2022-27961

Disclosure Date: April 10, 2022 (last updated February 23, 2025)
A cross-site scripting (XSS) vulnerability at /ofcms/company-c-47 in OFCMS v1.1.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Comment text box.
Attacker Value
Unknown

CVE-2022-27960

Disclosure Date: April 10, 2022 (last updated February 23, 2025)
Insecure permissions configured in the user_id parameter at SysUserController.java of OFCMS v1.1.4 allows attackers to access and arbitrarily modify users' personal information.
Attacker Value
Unknown

CVE-2019-9608

Disclosure Date: March 06, 2019 (last updated November 27, 2024)
An issue was discovered in OFCMS before 1.1.3. Remote attackers can execute arbitrary code because blocking of .jsp and .jspx files does not consider (for example) file.jsp::$DATA to the admin/ueditor/uploadImage URI.
0
Attacker Value
Unknown

CVE-2019-9614

Disclosure Date: March 06, 2019 (last updated November 27, 2024)
An issue was discovered in OFCMS before 1.1.3. A command execution vulnerability exists via a template file with '<#assign ex="freemarker.template.utility.Execute"?new()> ${ ex("' followed by the command.
0
Attacker Value
Unknown

CVE-2019-9610

Disclosure Date: March 06, 2019 (last updated November 27, 2024)
An issue was discovered in OFCMS before 1.1.3. It has admin/cms/template/getTemplates.html?res_path=res&up_dir=../ directory traversal, related to the getTemplates function in TemplateController.java.
0
Attacker Value
Unknown

CVE-2019-9611

Disclosure Date: March 06, 2019 (last updated November 27, 2024)
An issue was discovered in OFCMS before 1.1.3. It allows admin/cms/template/getTemplates.html?res_path=res directory traversal, with ../ in the dir parameter, to write arbitrary content (in the file_content parameter) into an arbitrary file (specified by the file_name parameter). This is related to the save function in TemplateController.java.
0
Attacker Value
Unknown

CVE-2019-9615

Disclosure Date: March 06, 2019 (last updated November 27, 2024)
An issue was discovered in OFCMS before 1.1.3. It allows admin/system/generate/create?sql= SQL injection, related to SystemGenerateController.java.
0