2786 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2020-37019
Orchard Core Web
5.1
MEDIUM
EPSS
0.1%
2020 CWE-79 1 PoC

Orchard Core RC1 contains a persistent cross-site scripting vulnerability that allows remote attackers to inject malicious scripts through blog post creation. Attackers can create blog posts with embedded JavaScript in the MarkdownBodyPart.Source parameter to execute arbitrary scripts in victim browsers.

CVE-2020-36966
Dolibarr Web Windows
5.1
MEDIUM
EPSS
0.0%
2020 CWE-79 1 PoC

Dolibarr 11.0.3 contains a persistent cross-site scripting vulnerability in LDAP synchronization settings that allows attackers to inject malicious scripts through multiple parameters. Attackers can exploit the host, slave, and port parameters in /dolibarr/admin/ldap.php to execute arbitrary JavaScript and potentially steal user cookie information.

CVE-2020-36905
Home Center 3 Web
5.1
MEDIUM
EPSS
0.1%
2020 CWE-829 2 PoCs

FIBARO System Home Center 5.021 contains a remote file inclusion vulnerability in the undocumented proxy API that allows attackers to include arbitrary client-side scripts. Attackers can exploit the 'url' GET parameter to inject malicious JavaScript and potentially hijack user sessions or manipulate page content.

CVE-2020-37106
Business Live Chat Software Web
5.1
MEDIUM
EPSS
0.0%
2020 CWE-352 1 PoC

Business Live Chat Software 1.0 contains a cross-site request forgery vulnerability that allows attackers to change user account roles without authentication. Attackers can craft a malicious HTML form to modify user privileges by submitting a POST request to the user creation endpoint with administrative access parameters.

CVE-2020-37145
HRSALE Web
5.1
MEDIUM
EPSS
0.0%
2020 CWE-352 1 PoC

HRSALE 1.1.8 contains a cross-site request forgery vulnerability that allows attackers to add unauthorized administrative users through the employee registration form. Attackers can craft a malicious HTML page with hidden form fields to trick authenticated administrators into creating new user accounts with elevated privileges.

CVE-2020-37022
OpenZ ERP Web
5.1
MEDIUM
EPSS
0.0%
2020 CWE-79 4 PoCs

OpenZ ERP 3.6.60 contains a persistent cross-site scripting vulnerability in the Employee module's name and description parameters. Attackers can inject malicious scripts through POST requests to , enabling session hijacking and manipulation of application modules.

CVE-2020-36954
Xeroneit Library Management System Web
5.1
MEDIUM
EPSS
0.0%
2020 CWE-79 1 PoC

Xeroneit Library Management System 3.1 contains a stored cross-site scripting vulnerability in the Book Category feature that allows administrators to inject malicious scripts. Attackers can insert a payload in the Category Name field to execute arbitrary JavaScript code when the page is loaded.

CVE-2020-36998
E-Learning Suite Web
5.1
MEDIUM
EPSS
0.0%
2020 CWE-79 1 PoC

Forma.lms The E-Learning Suite 2.3.0.2 contains a persistent cross-site scripting vulnerability in multiple course and profile parameters. Attackers can inject malicious scripts in course code, name, description fields, and email parameter to execute arbitrary JavaScript without proper input sanitization.

CVE-2020-37118
FNIP-8x16A Web
5.1
MEDIUM
EPSS
0.0%
2020 CWE-352 2 PoCs

P5 FNIP-8x16A FNIP-4xSH 1.0.20 contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions without user interaction. Attackers can craft malicious web pages to add new admin users, change passwords, and modify system configurations by tricking authenticated users into loading a specially crafted page.

CVE-2020-19248
Software Genérico Web Database
5.1
MEDIUM
EPSS
0.0%
2020 1 PoC

SQL Injection vulnerability in PbootCMS 1.4.1 in parsing if statements in templates, resulting in a malicious user's ability to contaminate template content by searching for page contamination URLs, thus triggering vulnerabilities when the program uses eval statements to parse templates.

CVE-2020-36993
LimeSurvey Web
5.1
MEDIUM
EPSS
0.0%
2020 CWE-79 1 PoC

LimeSurvey 4.3.10 contains a stored cross-site scripting vulnerability in the Survey Menu functionality of the administration panel. Attackers can inject malicious SVG scripts through the Surveymenu[title] and Surveymenu[parent_id] parameters to execute arbitrary JavaScript in administrative contexts.

CVE-2020-36932
Seacms Web
5.1
MEDIUM
EPSS
0.0%
2020 CWE-79 1 PoC

SeaCMS 11.1 contains a stored cross-site scripting vulnerability in the checkuser parameter of the admin settings page. Attackers can inject malicious JavaScript payloads that will execute in users' browsers when the page is loaded.

CVE-2020-37103
DotNetNuke Web
5.1
MEDIUM
EPSS
0.1%
2020 CWE-79 1 PoC

DotNetNuke 9.5 contains a persistent cross-site scripting vulnerability that allows normal users to upload malicious XML files with executable scripts through journal tools. Attackers can upload XML files with XHTML namespace scripts to execute arbitrary JavaScript in users' browsers, potentially bypassing CSRF protections and performing more damaging attacks.

CVE-2020-37003
Sellacious eCommerce Web
5.1
MEDIUM
EPSS
0.0%
2020 CWE-79 2 PoCs

Sellacious eCommerce 4.6 contains a persistent cross-site scripting vulnerability in the Manage Your Addresses module that allows attackers to inject malicious scripts. Attackers can exploit multiple address input fields like full name, company, and address to execute persistent script code that can hijack user sessions and manipulate application modules.

CVE-2020-37046
Sistem Informasi Pengumuman Kelulusan Online Web
5.1
MEDIUM
EPSS
0.0%
2020 CWE-352 1 PoC

Sistem Informasi Pengumuman Kelulusan Online 1.0 contains a cross-site request forgery vulnerability that allows attackers to add unauthorized admin users through the tambahuser.php endpoint. Attackers can craft a malicious HTML form to submit admin credentials and create new administrative accounts without the victim's consent.

CVE-2020-37014
Tryton Web
5.1
MEDIUM
EPSS
0.1%
2020 CWE-79 2 PoCs

Tryton 5.4 contains a persistent cross-site scripting vulnerability in the user profile name input that allows remote attackers to inject malicious scripts. Attackers can exploit the vulnerability by inserting script payloads in the name field, which execute in the frontend and backend user interfaces.

CVE-2020-37018
GOautodial Web
5.1
MEDIUM
EPSS
0.0%
2020 CWE-79 1 PoC

GOautodial 4.0 contains a persistent cross-site scripting vulnerability that allows authenticated agents to inject malicious scripts through message subjects. Attackers can craft messages with embedded JavaScript that will execute when an administrator reads the message, potentially stealing session cookies or executing client-side attacks.

CVE-2020-36996
PHPFusion Web
5.1
MEDIUM
EPSS
0.1%
2020 CWE-79 1 PoC

PHPFusion 9.03.50 contains a persistent cross-site scripting vulnerability in the print.php page that fails to properly sanitize user-submitted message content. Attackers can inject malicious JavaScript through forum messages that will execute when the print page is generated, allowing script execution in victim browsers.

CVE-2020-36960
Forma LMS Web
5.1
MEDIUM
EPSS
0.0%
2020 CWE-79 1 PoC

Forma LMS 2.3 contains a stored cross-site scripting vulnerability that allows attackers to inject malicious scripts into user profile first and last name fields. Attackers can craft scripts like '<script>alert(document.cookie)</script>' to execute arbitrary JavaScript when the profile is viewed by other users.

CVE-2020-37111
60CycleCMS Web Database
5.1
MEDIUM
EPSS
0.0%
2020 CWE-79 1 PoC

60CycleCMS 2.5.2 contains a cross-site scripting (XSS) vulnerability in news.php that allows attackers to inject malicious scripts through GET parameters. Attackers can craft malicious URLs with XSS payloads targeting the 'etsu' and 'ltsu' parameters to execute arbitrary scripts in victim's browsers. This issue does not involve SQL injection.