Summary
Detail | |||
---|---|---|---|
Vendor | Wbce | First view | 2023-10-21 |
Product | Wbce Cms | Last view | 2023-11-10 |
Version | 1.6.0 | Type | Application |
Update | * | ||
Edition | * | ||
Language | * | ||
Sofware Edition | * | ||
Target Software | * | ||
Target Hardware | * | ||
Other | * | ||
CPE Product | cpe:2.3:a:wbce:wbce_cms |
Activity : Overall
Related : CVE
Date | Alert | Description | |
---|---|---|---|
9.8 | 2023-11-10 | CVE-2023-39796 | SQL injection vulnerability in the miniform module in WBCE CMS v.1.6.0 allows remote unauthenticated attacker to execute arbitrary code via the DB_RECORD_TABLE parameter. |
5.4 | 2023-10-21 | CVE-2023-46054 | Cross Site Scripting (XSS) vulnerability in WBCE CMS v.1.6.1 and before allows a remote attacker to escalate privileges via a crafted script to the website_footer parameter in the admin/settings/save.php component. |
CWE : Common Weakness Enumeration
% | id | Name |
---|---|---|
50% (1) | CWE-89 | Improper Sanitization of Special Elements used in an SQL Command ('... |
50% (1) | CWE-79 | Failure to Preserve Web Page Structure ('Cross-site Scripting') |