Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2019-9078

zzcms 2019 has XSS via an arbitrary user/ask.php?do=modify parameter because inc/stopsqlin.php does not block a mixed-case string such as sCrIpT.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 43.3%
CVSS Severity
CVSS v3 Score 5.4
CVSS v2 Score 3.5
Products affected by CVE-2019-9078
  • Zzcms » Zzcms » Version: 2019
    cpe:2.3:a:zzcms:zzcms:2019


Contact Us

Shodan ® - All rights reserved