Show filters
41 Total Results
Displaying 1-10 of 41
Sort by:
Attacker Value
Unknown
CVE-2024-24291
Disclosure Date: February 06, 2024 (last updated February 14, 2024)
An issue in the component /member/index/login of yzmcms v7.0 allows attackers to direct users to malicious sites via a crafted URL.
0
Attacker Value
Unknown
CVE-2023-52274
Disclosure Date: January 11, 2024 (last updated January 17, 2024)
member/index/register.html in YzmCMS 6.5 through 7.0 allows XSS via the Referer HTTP header.
0
Attacker Value
Unknown
CVE-2020-23595
Disclosure Date: August 11, 2023 (last updated October 08, 2023)
Cross Site Request Forgery (CSRF) vulnerability in yzmcms version 5.6, allows remote attackers to escalate privileges and gain sensitive information sitemodel/add.html endpoint.
0
Attacker Value
Unknown
CVE-2020-20502
Disclosure Date: June 20, 2023 (last updated October 08, 2023)
Cross Site Request Forgery found in yzCMS v.2.0 allows a remote attacker to execute arbitrary code via the token check function.
0
Attacker Value
Unknown
CVE-2021-36712
Disclosure Date: February 03, 2023 (last updated October 08, 2023)
Cross Site Scripting (XSS) vulnerability in yzmcms 6.1 allows attackers to steal user cookies via image clipping function.
0
Attacker Value
Unknown
CVE-2022-23383
Disclosure Date: March 10, 2022 (last updated February 23, 2025)
YzmCMS v6.3 is affected by broken access control. Without login, unauthorized access to the user's personal home page can be realized. It is necessary to judge the user's login status before accessing the personal home page, but the vulnerability can access other users' home pages through the non login status because real authentication is not carried out.
0
Attacker Value
Unknown
CVE-2022-23384
Disclosure Date: February 15, 2022 (last updated February 23, 2025)
YzmCMS v6.3 is affected by Cross Site Request Forgery (CSRF) in /admin.add
0
Attacker Value
Unknown
CVE-2022-23889
Disclosure Date: January 28, 2022 (last updated February 23, 2025)
The comment function in YzmCMS v6.3 was discovered as being able to be operated concurrently, allowing attackers to create an unusually large number of comments.
0
Attacker Value
Unknown
CVE-2022-23888
Disclosure Date: January 28, 2022 (last updated February 23, 2025)
YzmCMS v6.3 was discovered to contain a Cross-Site Request Forgey (CSRF) via the component /yzmcms/comment/index/init.html.
0
Attacker Value
Unknown
CVE-2022-23887
Disclosure Date: January 28, 2022 (last updated February 23, 2025)
YzmCMS v6.3 was discovered to contain a Cross-Site Request Forgery (CSRF) which allows attackers to arbitrarily delete user accounts via /admin/admin_manage/delete.
0