Vulnerabilities
20 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-1557 | A vulnerability, which was classified as problematic, was found in OFCMS 1.1.3. A vulnerability, which was classified as problematic, was found in OFCMS 1.1.3. Affected is an unknown function. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. NVD description · AI analysis pending | 5.3 | <1% | PoC |
| — | |
| CVE-2024-48236 +1 in the same advisory: …48235 | An issue in ofcms 1.1.2 allows a remote attacker to execute arbitrary code via the FileOutputStream function in the write String method of the ofcms-admin\src\m An issue in ofcms 1.1.2 allows a remote attacker to execute arbitrary code via the FileOutputStream function in the write String method of the ofcms-admin\src\main\java\com\ofsoft\cms\core\uitle\FileUtils.java file NVD description · AI analysis pending | 6.5 | <1% | PoC |
| — | |
| CVE-2024-9411 | A vulnerability classified as problematic has been found in OFCMS 1.1.2. A vulnerability classified as problematic has been found in OFCMS 1.1.2. This affects the function add of the file /admin/system/dict/add.json?sqlid=system.dict.save. The manipulation of the argument dict_value leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. NVD description · AI analysis pending | 5.3 | <1% |
| — | ||
| CVE-2024-34256 | OFCMS V1.1.2 is vulnerable to SQL Injection via the new table function. OFCMS V1.1.2 is vulnerable to SQL Injection via the new table function. NVD description · AI analysis pending | 9.8 | <1% | PoC |
| — | |
| CVE-2023-51807 | Cross Site Scripting vulnerability in OFCMS v.1.14 allows a remote attacker to obtain sensitive information via a crafted payload to the title addition componen Cross Site Scripting vulnerability in OFCMS v.1.14 allows a remote attacker to obtain sensitive information via a crafted payload to the title addition component. NVD description · AI analysis pending | 5.4 | <1% | PoC |
| — | |
| CVE-2023-24760 | An issue found in Ofcms v.1.1.4 allows a remote attacker to to escalate privileges via the respwd method in SysUserController. An issue found in Ofcms v.1.1.4 allows a remote attacker to to escalate privileges via the respwd method in SysUserController. NVD description · AI analysis pending | 8.8 | <1% | PoC |
| — | |
| CVE-2022-29653 | OFCMS v1.1.4 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /admin/comn/service/update.json. OFCMS v1.1.4 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /admin/comn/service/update.json. NVD description · AI analysis pending | 6.1 | <1% |
| — | ||
| CVE-2022-27960 +1 in the same advisory: …27961 | Insecure permissions configured in the user_id parameter at SysUserController.java of OFCMS v1.1.4 allows attackers to access and arbitrarily modify users' pers Insecure permissions configured in the user_id parameter at SysUserController.java of OFCMS v1.1.4 allows attackers to access and arbitrarily modify users' personal information. NVD description · AI analysis pending | 5.4 | <1% | PoC |
| — | |
| CVE-2019-9617 | An issue was discovered in OFCMS before 1.1.3. An issue was discovered in OFCMS before 1.1.3. Remote attackers can execute arbitrary code because blocking of .jsp and .jspx files does not consider (for example) file.jsp::$DATA to the admin/ueditor/uploadFile URI. NVD description · AI analysis pending | 8.8 group max | 3% | PoC |
| — |