Vulnerabilities
7 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2019-8439 | An issue was discovered in DiliCMS 2.4.0. An issue was discovered in DiliCMS 2.4.0. There is a Stored XSS Vulnerability in the second textbox of "System setting->site setting" of admin/index.php, aka site_domain. NVD description · AI analysis pending | 5.4 group max | <1% | PoC |
| — | |
| CVE-2018-19291 | An issue was discovered in DiliCMS 2.4.0. An issue was discovered in DiliCMS 2.4.0. There is a CSRF vulnerability that can delete a user or group via an admin/index.php/user/del/1 or admin/index.php/role/del/2 URI. NVD description · AI analysis pending | 6.5 | <1% | PoC |
| — | |
| CVE-2018-18210 +1 in the same advisory: …18209 | XSS exists in DiliCMS 2.4.0 via the admin/index.php/setting/site?tab=site_attachment attachment_url parameter. XSS exists in DiliCMS 2.4.0 via the admin/index.php/setting/site?tab=site_attachment attachment_url parameter. NVD description · AI analysis pending | 6.1 | <1% | PoC |
| — | |
| CVE-2018-10430 | An issue was discovered in DiliCMS (aka DiligentCMS) 2.4.0. An issue was discovered in DiliCMS (aka DiligentCMS) 2.4.0. There is a Stored XSS Vulnerability in the fourth textbox of "System setting->site setting" of admin/index.php. NVD description · AI analysis pending | 4.8 | <1% | PoC |
| — |