UJCMS是dromara开源的一个 Java 开源内容管理系统。 UJCMS 9.6.3版本存在安全漏洞,该漏洞源于对上传的SVG文件中嵌入属性清理不足,存在存储型跨站脚本(XSS)漏洞,允许经过身份验证的攻击者在其他后端用户的浏览器上下文中执行任意JavaScript,从而导致敏感令牌被盗。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2024-12478 | 6.3 MEDIUM | InvoicePlane 1 upload_file unrestricted upload |
| CVE-2024-12666 | 4.7 MEDIUM | ClassCMS User Management Page admin insufficient privileges |
| CVE-2024-12362 | 4.3 MEDIUM | InvoicePlane invoices.php download path traversal |
| CVE-2024-12667 | 3.7 LOW | InvoicePlane view session expiration |
| CVE-2024-52949 | IPTraf-ng 安全漏洞 | |
| CVE-2024-53376 | CyberPanel 安全漏洞 | |
| CVE-2024-29671 | NEXTU FLATA AX1500 安全漏洞 | |
| CVE-2024-56084 | Logpoint Universal Normalizer 安全漏洞 | |
| CVE-2024-56083 | Cognition Devin 安全漏洞 | |
| CVE-2024-56086 | Logpoint 安全漏洞 | |
| CVE-2024-56085 | Logpoint 安全漏洞 | |
| CVE-2024-56087 | Logpoint 安全漏洞 | |
| CVE-2024-56112 | CyberPanel 安全漏洞 | |
| CVE-2024-55104 | Online Nurse Hiring System 安全漏洞 | |
| CVE-2024-55100 | Online Nurse Hiring System 安全漏洞 | |
| CVE-2024-55452 | UJCMS 安全漏洞 | |
| CVE-2024-55554 | Intrexx Portal Server 安全漏洞 | |
| CVE-2024-55085 | GetSimple CMS 安全漏洞 | |
| CVE-2024-55557 | Weasis 安全漏洞 | |
| CVE-2024-55103 | Online Nurse Hiring System 安全漏洞 |
Showing top 20 of 25 CVEs. View all on vendor page → →
No comments yet