Show filters
5 Total Results
Displaying 1-5 of 5
Sort by:
Attacker Value
Unknown

CVE-2024-41600

Disclosure Date: July 19, 2024 (last updated August 23, 2024)
Insecure Permissions vulnerability in lin-CMS Springboot v.0.2.1 and before allows a remote attacker to obtain sensitive information via the login method in the UserController.java component.
Attacker Value
Unknown

CVE-2022-32430

Disclosure Date: July 21, 2022 (last updated October 07, 2023)
An access control issue in Lin CMS Spring Boot v0.2.1 allows attackers to access the backend information and functions within the application.
Attacker Value
Unknown

CVE-2020-18701

Disclosure Date: August 16, 2021 (last updated November 29, 2024)
Incorrect Access Control in Lin-CMS-Flask v0.1.1 allows remote attackers to obtain sensitive information and/or gain privileges due to the application not invalidating a user's authentication token upon logout, which allows for replaying packets.
Attacker Value
Unknown

CVE-2020-18699

Disclosure Date: August 16, 2021 (last updated November 29, 2024)
Cross Site Scripting (XSS) in Lin-CMS-Flask v0.1.1 allows remote attackers to execute arbitrary code by entering scripts in the the 'Username' parameter of the in component 'app/api/cms/user.py'.
Attacker Value
Unknown

CVE-2020-18698

Disclosure Date: August 16, 2021 (last updated November 29, 2024)
Improper Authentication in Lin-CMS-Flask v0.1.1 allows remote attackers to launch brute force login attempts without restriction via the 'login' function in the component 'app/api/cms/user.py'.