VYPR

CMS

by Getsymphony

CVEs (2)

  • CVE-2020-15071MedAug 11, 2020
    risk 0.40cvss 6.1epss 0.01

    content/content.blueprintsevents.php in Symphony CMS 3.0.0 allows XSS via fields['name'] to appendSubheading.

  • CVE-2010-3458Sep 17, 2010
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in lib/toolkit/events/event.section.php in Symphony CMS 2.0.7 and 2.1.1 allows remote attackers to execute arbitrary SQL commands via the send-email[recipient] parameter to about/. NOTE: some of these details are obtained from third party information.