Vulnerabilities
Vulnerable Software
Dilicms:  >> Dilicms  Security Vulnerabilities
An issue was discovered in DiliCMS 2.4.0. There is a Stored XSS Vulnerability in the first textbox of "System setting->site setting" of admin/index.php, aka site_name.
CVSS Score
4.8
EPSS Score
0.002
Published
2019-03-07
An issue was discovered in DiliCMS 2.4.0. There is a Stored XSS Vulnerability in the second textbox of "System setting->site setting" of admin/index.php, aka site_domain.
CVSS Score
5.4
EPSS Score
0.002
Published
2019-03-07
An issue was discovered in DiliCMS 2.4.0. There is a Stored XSS Vulnerability in the third textbox (aka site logo) of "System setting->site setting" of admin/index.php, aka site_logo.
CVSS Score
4.8
EPSS Score
0.002
Published
2019-03-07
An issue was discovered in DiliCMS 2.4.0. There is a CSRF vulnerability that can delete a user or group via an admin/index.php/user/del/1 or admin/index.php/role/del/2 URI.
CVSS Score
6.5
EPSS Score
0.0
Published
2018-11-15
XSS exists in DiliCMS 2.4.0 via the admin/index.php/setting/site?tab=site_attachment attachment_type parameter.
CVSS Score
6.1
EPSS Score
0.002
Published
2018-10-10
XSS exists in DiliCMS 2.4.0 via the admin/index.php/setting/site?tab=site_attachment attachment_url parameter.
CVSS Score
6.1
EPSS Score
0.002
Published
2018-10-10
An issue was discovered in DiliCMS (aka DiligentCMS) 2.4.0. There is a Stored XSS Vulnerability in the fourth textbox of "System setting->site setting" of admin/index.php.
CVSS Score
4.8
EPSS Score
0.002
Published
2018-04-26


Contact Us

Shodan ® - All rights reserved