ZeroHour

Vulnerabilities

7 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2019-8439
+2 in the same advisory: …8440 …8438
An issue was discovered in DiliCMS 2.4.0.

An issue was discovered in DiliCMS 2.4.0. There is a Stored XSS Vulnerability in the second textbox of "System setting->site setting" of admin/index.php, aka site_domain.

NVD description · AI analysis pending
5.4
group max
<1% PoC
  • dilicms dilicms
CVE-2018-19291
An issue was discovered in DiliCMS 2.4.0.

An issue was discovered in DiliCMS 2.4.0. There is a CSRF vulnerability that can delete a user or group via an admin/index.php/user/del/1 or admin/index.php/role/del/2 URI.

NVD description · AI analysis pending
6.5<1% PoC
  • dilicms dilicms
CVE-2018-18210
+1 in the same advisory: …18209
XSS exists in DiliCMS 2.4.0 via the admin/index.php/setting/site?tab=site_attachment attachment_url parameter.

XSS exists in DiliCMS 2.4.0 via the admin/index.php/setting/site?tab=site_attachment attachment_url parameter.

NVD description · AI analysis pending
6.1<1% PoC
  • dilicms dilicms
CVE-2018-10430
An issue was discovered in DiliCMS (aka DiligentCMS) 2.4.0.

An issue was discovered in DiliCMS (aka DiligentCMS) 2.4.0. There is a Stored XSS Vulnerability in the fourth textbox of "System setting->site setting" of admin/index.php.

NVD description · AI analysis pending
4.8<1% PoC
  • dilicms dilicms