Summary
Detail | |||
---|---|---|---|
Vendor | Chaoji Cms Project | First view | 2021-10-14 |
Product | Chaoji Cms | Last view | 2023-06-27 |
Version | Type | Application | |
Update | |||
Edition | |||
Language | |||
Sofware Edition | |||
Target Software | |||
Target Hardware | |||
Other |
Activity : Overall
COMMON PLATFORM ENUMERATION: Repartition per Version
CPE Name | Affected CVE |
---|---|
cpe:2.3:a:chaoji_cms_project:chaoji_cms:2.18:*:*:*:*:*:*:* | 3 |
cpe:2.3:a:chaoji_cms_project:chaoji_cms:2.39:*:*:*:*:*:*:* | 1 |
Related : CVE
Date | Alert | Description | |
---|---|---|---|
4.8 | 2023-06-27 | CVE-2020-18414 | Stored cross site scripting (XSS) vulnerability in Chaoji CMS v2.18 that allows attackers to execute arbitrary code via /index.php?admin-master-webset. |
4.8 | 2023-06-27 | CVE-2020-18413 | Stored cross site scripting (XSS) vulnerability in /index.php?admin-master-navmenu-add of Chaoji CMS v2.18 that allows attackers to execute arbitrary code. |
4.8 | 2023-06-27 | CVE-2020-18410 | A stored cross site scripting (XSS) vulnerability in /index.php?admin-master-article-edit of Chaoji CMS v2.18 that allows attackers to obtain administrator privileges. |
5.4 | 2021-10-14 | CVE-2020-19962 | A stored cross-site scripting (XSS) vulnerability in the getClientIp function in /lib/tinwin.class.php of Chaoji CMS 2.39, allows attackers to execute arbitrary web scripts. |
CWE : Common Weakness Enumeration
% | id | Name |
---|---|---|
100% (4) | CWE-79 | Failure to Preserve Web Page Structure ('Cross-site Scripting') |