ZeroHour

Vulnerabilities

10 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-26951
onekeyadmin v1.3.9 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Member List module.

onekeyadmin v1.3.9 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Member List module.

NVD description · AI analysis pending
5.4<1%
  • onekeyadmin onekeyadmin
CVE-2023-26957
+1 in the same advisory: …26948
onekeyadmin v1.3.9 was discovered to contain an arbitrary file delete vulnerability via the component \admin\controller\plugins.

onekeyadmin v1.3.9 was discovered to contain an arbitrary file delete vulnerability via the component \admin\controller\plugins.

NVD description · AI analysis pending
9.1
group max
<1% PoC
  • onekeyadmin onekeyadmin
CVE-2023-26956
+2 in the same advisory: …26952 …26950
onekeyadmin v1.3.9 was discovered to contain an arbitrary file read vulnerability via the component /admin1/curd/code.

onekeyadmin v1.3.9 was discovered to contain an arbitrary file read vulnerability via the component /admin1/curd/code.

NVD description · AI analysis pending
7.5
group max
<1% PoC
  • onekeyadmin onekeyadmin
CVE-2023-26953
onekeyadmin v1.3.9 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Add Administrator module.

onekeyadmin v1.3.9 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Add Administrator module.

NVD description · AI analysis pending
4.8<1% PoC
  • onekeyadmin onekeyadmin
CVE-2023-26954
+1 in the same advisory: …26955
onekeyadmin v1.3.9 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the User Group module.

onekeyadmin v1.3.9 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the User Group module.

NVD description · AI analysis pending
5.4<1% PoC
  • onekeyadmin project onekeyadmin
CVE-2023-26949
An arbitrary file upload vulnerability in the component /admin1/config/update of onekeyadmin v1.3.9 allows attackers to execute arbitrary code via a crafted PHP

An arbitrary file upload vulnerability in the component /admin1/config/update of onekeyadmin v1.3.9 allows attackers to execute arbitrary code via a crafted PHP file.

NVD description · AI analysis pending
9.8<1% PoC
  • onekeyadmin onekeyadmin