ZeroHour

Vulnerabilities

9 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2021-45017
+1 in the same advisory: …45018
Cross Site Request Forgery (CSRF) vulnerability exits in Catfish <=6.1.* when you upload an html file containing CSRF on the website that uses a google editor;

Cross Site Request Forgery (CSRF) vulnerability exits in Catfish <=6.1.* when you upload an html file containing CSRF on the website that uses a google editor; you can specify the menu url address as your malicious url address in the Add Menu column.

NVD description · AI analysis pending
8.8
group max
<1% PoC
  • catfish-cms catfish cms
CVE-2020-23962
A cross site scripting (XSS) vulnerability in Catfish CMS 4.9.90 allows attackers to execute arbitrary web scripts or HTML via a crafted payload entered into th

A cross site scripting (XSS) vulnerability in Catfish CMS 4.9.90 allows attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "announcement_gonggao" parameter.

NVD description · AI analysis pending
6.1<1% PoC
  • catfish-cms catfish cms
CVE-2018-18735
+1 in the same advisory: …18736
A CSRF issue was discovered in admin/Index/tiquan in catfish blog 2.0.33.

A CSRF issue was discovered in admin/Index/tiquan in catfish blog 2.0.33.

NVD description · AI analysis pending
8.8
group max
<1% PoC
  • catfish-cms catfish blog
CVE-2018-18734
+1 in the same advisory: …18733
A CSRF issue was discovered in admin/Index/addmanageuser.html in Catfish CMS 4.8.30.

A CSRF issue was discovered in admin/Index/addmanageuser.html in Catfish CMS 4.8.30.

NVD description · AI analysis pending
8.8
group max
<1% PoC
  • catfish-cms catfish cms
CVE-2018-13999
Catfish CMS v4.7.9 allows XSS via the admin/Index/write.html editorValue parameter (aka an article posted by an administrator).

Catfish CMS v4.7.9 allows XSS via the admin/Index/write.html editorValue parameter (aka an article posted by an administrator).

NVD description · AI analysis pending
4.8<1% PoC
  • catfish-cms catfish cms
CVE-2018-10023
Catfish CMS V4.7.21 allows XSS via the pinglun parameter to cat/index/index/pinglun (aka an authenticated comment).

Catfish CMS V4.7.21 allows XSS via the pinglun parameter to cat/index/index/pinglun (aka an authenticated comment).

NVD description · AI analysis pending
5.4<1% PoC
  • catfish-cms catfish cms