2786 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2020-36996
PHPFusion Web
5.1
MEDIUM
EPSS
0.1%
2020 CWE-79 1 PoC

PHPFusion 9.03.50 contains a persistent cross-site scripting vulnerability in the print.php page that fails to properly sanitize user-submitted message content. Attackers can inject malicious JavaScript through forum messages that will execute when the print page is generated, allowing script execution in victim browsers.

CVE-2020-36960
Forma LMS Web
5.1
MEDIUM
EPSS
0.0%
2020 CWE-79 1 PoC

Forma LMS 2.3 contains a stored cross-site scripting vulnerability that allows attackers to inject malicious scripts into user profile first and last name fields. Attackers can craft scripts like '<script>alert(document.cookie)</script>' to execute arbitrary JavaScript when the profile is viewed by other users.

CVE-2020-36931
Click2Magic Web
5.1
MEDIUM
EPSS
0.0%
2020 CWE-79 1 PoC

Click2Magic 1.1.5 contains a stored cross-site scripting vulnerability that allows attackers to inject malicious scripts in the chat name input. Attackers can craft a malicious payload in the chat name to capture administrator cookies when the admin processes user requests.

CVE-2020-36918
iDS6 DSSPro Digital Signage System Web
5.1
MEDIUM
EPSS
0.0%
2020 CWE-352 2 PoCs

iDS6 DSSPro Digital Signage System 6.2 contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions without request validation. Attackers can craft malicious web pages to trick logged-in administrators into adding unauthorized users by exploiting the lack of CSRF protections.

CVE-2020-36908
SnapGear Management Console SG560 Web
5.1
MEDIUM
EPSS
0.1%
2020 CWE-352 2 PoCs

SnapGear Management Console SG560 version 3.1.5 contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions without user consent. Attackers can craft a malicious web page that automatically submits a form to create a new super user account with full administrative privileges when a logged-in user visits the page.

CVE-2020-37152
PHP-Fusion Web
5.1
MEDIUM
EPSS
0.0%
2020 CWE-79 1 PoC

PHP-Fusion 9.03.50 panels.php is vulnerable to cross-site scripting (XSS) via the 'panel_content' POST parameter. The application fails to properly sanitize user input before rendering it in the browser, allowing attackers to inject arbitrary JavaScript. This can be exploited by submitting crafted input to the 'panel_content' field in panels.php, resulting in execution of malicious scripts in the context of the affected site.

CVE-2020-37091
Maian Support Helpdesk Web
5.1
MEDIUM
EPSS
0.0%
2020 CWE-352 1 PoC

Maian Support Helpdesk 4.3 contains a cross-site request forgery vulnerability that allows attackers to create administrative accounts without authentication. Attackers can craft malicious HTML forms to add admin users and upload PHP files with unrestricted file upload capabilities through the FAQ attachment system.

CVE-2020-37144
Sysguard 6001 Web
5.1
MEDIUM
EPSS
0.0%
2020 CWE-352 1 PoC

Exagate SYSGuard 6001 contains a cross-site request forgery vulnerability that allows attackers to create unauthorized admin accounts through a crafted HTML form. Attackers can trick users into submitting a malicious form to /kulyon.php that adds a new user with administrative privileges without the victim's consent.

CVE-2020-37096
EW-7438RPn Mini Web
5.1
MEDIUM
EPSS
0.0%
2020 CWE-352 1 PoC

Edimax EW-7438RPn 1.13 contains a cross-site request forgery vulnerability in the MAC filtering configuration interface. Attackers can craft malicious web pages to trick users into adding unauthorized MAC addresses to the device's filtering rules without their consent.

CVE-2020-36978
Froxlor Froxlor Server Management Panel Web
5.1
MEDIUM
EPSS
0.0%
2020 CWE-79 2 PoCs

Froxlor Server Management Panel 0.10.16 contains a persistent cross-site scripting vulnerability in customer registration input fields. Attackers can inject malicious scripts through username, name, and firstname parameters to execute code when administrators view customer traffic modules.

CVE-2020-37054
Navigate CMS Web
5.1
MEDIUM
EPSS
0.0%
2020 CWE-352 1 PoC

Navigate CMS 2.8.7 contains a cross-site request forgery vulnerability that allows attackers to upload malicious extensions through a crafted HTML page. Attackers can trick authenticated administrators into executing arbitrary file uploads by leveraging the extension upload functionality without additional validation.

CVE-2020-37233
Buddypress Web Windows
5.1
MEDIUM
EPSS
0.0%
2020 CWE-79 1 PoC

WordPress Plugin Buddypress 6.2.0 contains a persistent cross-site scripting vulnerability that allows authenticated attackers with moderator privileges to inject malicious script code through the figure parameter in wp:html blocks. Attackers can inject iframe elements with event handlers like onload that execute when administrators or privileged users preview or view the affected page content, enabling session hijacking and persistent phishing attacks.

CVE-2020-37225
WHOIS Domain Check Web
5.1
MEDIUM
EPSS
0.0%
2020 CWE-79 1 PoC

Powie's WHOIS Domain Check 0.9.31 contains a persistent cross-site scripting vulnerability that allows authenticated attackers to inject arbitrary JavaScript by exploiting unsanitized input fields in plugin settings. Attackers can submit malicious payloads through textarea and input elements in the pwhois_settings.php configuration page to execute JavaScript in the admin context and escalate privileges.

CVE-2020-37148
FNIP-8x16A Web
5.1
MEDIUM
EPSS
0.0%
2020 CWE-79 2 PoCs

P5 FNIP-8x16A/FNIP-4xSH versions 1.0.20 and 1.0.11 suffer from a stored cross-site scripting vulnerability. Input passed to several GET/POST parameters is not properly sanitized before being returned to the user, allowing attackers to execute arbitrary HTML and script code in a user's browser session in the context of the affected site. This can be exploited by submitting crafted input to the label modification functionality, such as the 'lab4' parameter in config.html.

CVE-2020-36891
Xperience Web
5.1
MEDIUM
EPSS
0.1%
2020 CWE-79 1 PoC

A stored cross-site scripting vulnerability in Kentico Xperience allows attackers to upload files with spoofed Content-Type that do not match file extensions. Attackers can exploit this vulnerability by uploading malicious files with manipulated MIME types, allowing malicious scripts to execute in users' browsers.

CVE-2020-27146
TIBCO iProcess Workspace (Browser) Web
5.0
MEDIUM
EPSS
0.1%
2020 1 PoC

The Core component of TIBCO Software Inc.'s TIBCO iProcess Workspace (Browser) contains a vulnerability that theoretically allows an unauthenticated attacker with network access to execute a Cross Site Request Forgery (CSRF) attack on the affected system. A successful attack using this vulnerability requires human interaction from an authenticated user other than the attacker. Affected releases are TIBCO Software Inc.'s TIBCO iProcess Workspace (Browser): versions 11.6.0 and below.

CVE-2020-2912
PeopleSoft Enterprise CS Campus Community Web Database
5.0
MEDIUM
EPSS
0.3%
2020 1 PoC

Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Self-Service). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise CS Campus Community. While the vulnerability is in PeopleSoft Enterprise CS Campus Community, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized read access to a subset of PeopleSoft Enterprise CS Campus Community accessible data. CVS

CVE-2020-7269
McAfee Advanced Threat Defense (ATD) Web
4.9
MEDIUM
EPSS
0.1%
2020 CWE-200 1 PoC

Exposure of Sensitive Information in the web interface in McAfee Advanced Threat Defense (ATD) prior to 4.12.2 allows remote authenticated users to view sensitive unencrypted information via a carefully crafted HTTP request parameter. The risk is partially mitigated if your ATD instances are deployed as recommended with no direct access from the Internet to them.

CVE-2020-7270
McAfee Advanced Threat Defense (ATD) Web
4.9
MEDIUM
EPSS
0.2%
2020 CWE-200 1 PoC

Exposure of Sensitive Information in the web interface in McAfee Advanced Threat Defense (ATD) prior to 4.12.2 allows remote authenticated users to view sensitive unencrypted information via a carefully crafted HTTP request parameter. The risk is partially mitigated if your ATD instances are deployed as recommended with no direct access from the Internet to them.

CVE-2020-14622
WebLogic Server Web Database
4.9
MEDIUM
EPSS
0.7%
2020 1 PoC

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 4.9 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A