Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Zhhhy

#18908of 53,634
14.2Total CVSS
Vulnerabilities · 2
Medium
1
High
1
PT-2021-10387
8.8
2021-12-09
Zzcms · Zzcms · CVE-2020-19682
Name of the Vulnerable Software and Affected Versions: ZZZCMS version 1.7.1 Description: A Cross Site Request Forgery (CSRF) issue exists via the `save user` function in the "save.php" endpoint. This allows for unauthorized actions to be performed on behalf of a user. Recommendations: For ZZZCMS version 1.7.1, as a temporary workaround, consider disabling the `save user` function in save.php until a patch is available. Restrict access to the save.php endpoint to minimize the risk of exploitation.
PT-2021-10388
5.4
2021-12-09
Zzcms · Zzcms · CVE-2020-19683
Name of the Vulnerable Software and Affected Versions: ZZZCMS version 1.7.1 Description: A Cross Site Scripting (XSS) issue exists via an editfile action in the "save.php" endpoint. This allows for potential malicious script execution. Recommendations: For ZZZCMS version 1.7.1, consider restricting access to the "save.php" endpoint until a fix is available. As a temporary workaround, avoid using the editfile action in save.php to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.