Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Dreamsroid

#26607of 53,624
9.6Total CVSS
Vulnerabilities · 2
Medium
2
PT-2018-15128
4.8
2018-12-04
Yzmcms · Yzmcms · CVE-2018-19849
**Name of the Vulnerable Software and Affected Versions** YzmCMS version 5.2 **Description** An issue exists in the software where XSS is possible via the `searinfo` parameter in the "admin/content/search.html" endpoint. **Recommendations** For YzmCMS version 5.2, consider restricting access to the `searinfo` parameter in the "admin/content/search.html" endpoint to minimize the risk of exploitation.
PT-2018-14595
4.8
2018-10-28
Eleanor · Eleanor Cms · CVE-2018-18717
**Name of the Vulnerable Software and Affected Versions** Eleanor CMS versions prior to 2015-03-19 **Description** A security issue exists in the software, where XSS is possible via the "ajax.php?direct=admin&file=autocomplete&query=[XSS]" URI. This allows for potential exploitation. **Recommendations** For versions prior to 2015-03-19, as a temporary workaround, consider restricting access to the "ajax.php" endpoint, specifically the 'autocomplete' file with 'direct' parameter set to 'admin', until a fix is available.