xiaohuanxiong
CVEs (2)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-26268 | Cri | 0.64 | 9.8 | 0.01 | Mar 28, 2022 | Xiaohuanxiong v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /app/controller/Books.php. | ||
| CVE-2021-43737 | Med | 0.42 | 6.5 | 0.00 | Mar 23, 2022 | An issus was discovered in xiaohuanxiong CMS 5.0.17. There is a CSRF vulnerability that can modify administrator account's password. |
- risk 0.64cvss 9.8epss 0.01
Xiaohuanxiong v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /app/controller/Books.php.
- risk 0.42cvss 6.5epss 0.00
An issus was discovered in xiaohuanxiong CMS 5.0.17. There is a CSRF vulnerability that can modify administrator account's password.