Elefant CMS是加拿大John de Plume个人开发者的一个简单 PHP 内容管理系统和 Web 框架。 Elefant CMS 1.3.12-RC 版本存在跨站脚本漏洞,攻击者利用该漏洞可执行跨站点脚本攻击。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2017-20063 | 6.3 MEDIUM | Elefant CMS File Upload drop privileges management |
| CVE-2017-20064 | 6.3 MEDIUM | Elefant CMS layout code injection |
| CVE-2017-20062 | 5.0 MEDIUM | Elefant CMS cross-site request forgery |
| CVE-2017-20057 | 4.3 MEDIUM | Elefant CMS Persistent cross site scriting |
| CVE-2017-20058 | 4.3 MEDIUM | Elefant CMS Version Comparison Persistent cross site scriting |
| CVE-2017-20059 | 3.5 LOW | Elefant CMS Title Persistent cross site scriting |
| CVE-2017-20060 | 3.5 LOW | Elefant CMS Blog Post Persistent cross site scriting |
No comments yet