Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Mntn0X

#19479of 53,635
13.6Total CVSS
Vulnerabilities · 2
Medium
1
High
1
PT-2021-10478
7.5
2021-09-01
Yzmcms · Yzmcms · CVE-2020-20341
Name of the Vulnerable Software and Affected Versions: YzmCMS version 5.5 Description: The issue is related to a server-side request forgery (SSRF) in the `grab image()` function. This allows for potential unauthorized access to internal resources. Recommendations: For YzmCMS version 5.5, as a temporary workaround, consider disabling the `grab image()` function until a patch is available. Restrict access to the `grab image()` function to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
PT-2020-15460
6.1
2020-11-19
Yzmcms · Yzmcms · CVE-2020-22394
**Name of the Vulnerable Software and Affected Versions** YzmCMS version 5.5 **Description** The member contribution function in the editor of YzmCMS contains a cross-site scripting (XSS) issue. This allows for potential malicious script injection and execution. No information is provided about the estimated number of potentially affected devices worldwide or real-world incidents where this issue was exploited. **Recommendations** For YzmCMS version 5.5, consider disabling the member contribution function in the editor until a patch is available to mitigate the risk of cross-site scripting (XSS) attacks.