Known Vulnerabilities for products from Dbhcms Project
Listed below are 15 of the newest known vulnerabilities associated with the vendor "Dbhcms Project".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2020-19891 json | DBHcms v1.2.0 has an Arbitrary file write vulnerability in dbhcms\mod\mod.editor.php $_POST['updatefile'] is filename and $_P... | 7.2 - HIGH | 2020-08-24 | 2020-08-25 |
| CVE-2020-19890 json | DBHcms v1.2.0 has an Arbitrary file read vulnerability in dbhcms\mod\mod.editor.php $_GET['file'] is filename,and as there is... | 4.9 - MEDIUM | 2020-08-24 | 2021-07-21 |
| CVE-2020-19889 json | DBHcms v1.2.0 has no CSRF protection mechanism,as demonstrated by CSRF for index.php?dbhcms_pid=-70 can add a user. | 8.8 - HIGH | 2020-08-24 | 2020-08-26 |
| CVE-2020-19888 json | DBHcms v1.2.0 has an unauthorized operation vulnerability because there's no access control at line 175 of dbhcms\page.php fo... | 5.9 - MEDIUM | 2020-08-24 | 2021-07-21 |
| CVE-2020-19887 json | DBHcms v1.2.0 has a stored XSS vulnerability as there is no htmlspecialchars function for '$_POST['pageparam_insert_descripti... | 4.8 - MEDIUM | 2020-08-24 | 2020-08-25 |
| CVE-2020-19886 json | DBHcms v1.2.0 has no CSRF protection mechanism,as demonstrated by CSRF for an /index.php?dbhcms_pid=-80&deletemenu=9 can dele... | 8.1 - HIGH | 2020-08-24 | 2020-08-25 |
| CVE-2020-19885 json | DBHcms v1.2.0 has a stored xss vulnerability as there is no htmlspecialchars function for '$_POST['pageparam_insert_name']' v... | 4.8 - MEDIUM | 2020-08-24 | 2020-08-25 |
| CVE-2020-19884 json | DBHcms v1.2.0 has a stored xss vulnerability as there is no htmlspecialchars function in dbhcms\mod\mod.domain.edit.php line ... | 4.8 - MEDIUM | 2020-08-24 | 2020-08-25 |
| CVE-2020-19883 json | DBHcms v1.2.0 has a stored xss vulnerability as there is no security filter in dbhcms\mod\mod.users.view.php line 57 for user... | 4.8 - MEDIUM | 2020-08-24 | 2020-08-25 |
| CVE-2020-19882 json | DBHcms v1.2.0 has a stored xss vulnerability as there is no htmlspecialchars function for 'menu_description' variable in dbhc... | 4.8 - MEDIUM | 2020-08-24 | 2020-08-25 |
| CVE-2020-19881 json | DBHcms v1.2.0 has a reflected xss vulnerability as there is no security filter in dbhcms\mod\mod.selector.php line 108 for $_... | 4.8 - MEDIUM | 2020-08-24 | 2020-08-25 |
| CVE-2020-19880 json | DBHcms v1.2.0 has a stored xss vulnerability as there is no htmlspecialchars function form 'Name' in dbhcms\types.php, A remo... | 6.1 - MEDIUM | 2020-08-24 | 2020-08-25 |
| CVE-2020-19879 json | DBHcms v1.2.0 has a stored xss vulnerability as there is no security filter of $_GET['dbhcms_pid'] variable in dbhcms\page.ph... | 6.1 - MEDIUM | 2020-08-24 | 2020-08-25 |
| CVE-2020-19878 json | DBHcms v1.2.0 has a sensitive information leaks vulnerability as there is no security access control in /dbhcms/ext/news/ext.... | 7.5 - HIGH | 2020-08-24 | 2021-07-21 |
| CVE-2020-19877 json | DBHcms v1.2.0 has a directory traversal vulnerability as there is no directory control function in directory /dbhcms/. A remo... | 5.3 - MEDIUM | 2020-08-24 | 2020-08-25 |
Known software with vulnerabilities from Dbhcms Project
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Dbhcms Project | Dbhcms | 1.1.2 |