ZeroHour

Vulnerabilities

2 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2018-20367
The "mall some commodity details:

The "mall some commodity details: commodity consultation" component in WSTMart 2.0.8_181212 has stored XSS via the consultContent parameter, as demonstrated by the index.php/home/goodsconsult/add.html URI.

NVD description · AI analysis pending
6.1<1% PoC
  • wstmart wstmart
CVE-2018-19138
WSTMart 2.0.7 has CSRF via the index.php/admin/staffs/add.html URI.

WSTMart 2.0.7 has CSRF via the index.php/admin/staffs/add.html URI.

NVD description · AI analysis pending
8.82% PoC ×2
  • wstmart wstmart