Known Vulnerabilities for Dbhcms by Dbhcms Project
Listed below are 10 of the newest known vulnerabilities associated with "Dbhcms" by "Dbhcms Project".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2020-19891 json | DBHcms v1.2.0 has an Arbitrary file write vulnerability in dbhcms\mod\mod.editor.php $_POST['updatefile'] is filename and $_P... | 7.2 - HIGH | 2020-08-24 | 2020-08-25 |
| CVE-2020-19890 json | DBHcms v1.2.0 has an Arbitrary file read vulnerability in dbhcms\mod\mod.editor.php $_GET['file'] is filename,and as there is... | 4.9 - MEDIUM | 2020-08-24 | 2021-07-21 |
| CVE-2020-19889 json | DBHcms v1.2.0 has no CSRF protection mechanism,as demonstrated by CSRF for index.php?dbhcms_pid=-70 can add a user. | 8.8 - HIGH | 2020-08-24 | 2020-08-26 |
| CVE-2020-19888 json | DBHcms v1.2.0 has an unauthorized operation vulnerability because there's no access control at line 175 of dbhcms\page.php fo... | 5.9 - MEDIUM | 2020-08-24 | 2021-07-21 |
| CVE-2020-19887 json | DBHcms v1.2.0 has a stored XSS vulnerability as there is no htmlspecialchars function for '$_POST['pageparam_insert_descripti... | 4.8 - MEDIUM | 2020-08-24 | 2020-08-25 |
| CVE-2020-19886 json | DBHcms v1.2.0 has no CSRF protection mechanism,as demonstrated by CSRF for an /index.php?dbhcms_pid=-80&deletemenu=9 can dele... | 8.1 - HIGH | 2020-08-24 | 2020-08-25 |
| CVE-2020-19885 json | DBHcms v1.2.0 has a stored xss vulnerability as there is no htmlspecialchars function for '$_POST['pageparam_insert_name']' v... | 4.8 - MEDIUM | 2020-08-24 | 2020-08-25 |
| CVE-2020-19884 json | DBHcms v1.2.0 has a stored xss vulnerability as there is no htmlspecialchars function in dbhcms\mod\mod.domain.edit.php line ... | 4.8 - MEDIUM | 2020-08-24 | 2020-08-25 |
| CVE-2020-19883 json | DBHcms v1.2.0 has a stored xss vulnerability as there is no security filter in dbhcms\mod\mod.users.view.php line 57 for user... | 4.8 - MEDIUM | 2020-08-24 | 2020-08-25 |
| CVE-2020-19882 json | DBHcms v1.2.0 has a stored xss vulnerability as there is no htmlspecialchars function for 'menu_description' variable in dbhc... | 4.8 - MEDIUM | 2020-08-24 | 2020-08-25 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Dbhcms Project | Dbhcms | 1.2.0 | |||
| Application | Dbhcms Project | Dbhcms | 1.1.4 | |||
| Application | Dbhcms Project | Dbhcms | 1.1.3 | |||
| Application | Dbhcms Project | Dbhcms | 1.1.2 |