VYPR

Wuzhi CMS

by Wuzhi CMS Project

CVEs (8)

  • CVE-2018-17852CriOct 1, 2018
    risk 0.64cvss 9.8epss 0.02

    A SQL injection was discovered in WUZHI CMS 4.1.0 in coreframe/app/coupon/admin/card.php via the groupname parameter to the /index.php?m=coupon&f=card&v=detail_listing URI.

  • CVE-2018-15894CriAug 27, 2018
    risk 0.64cvss 9.8epss 0.02

    A SQL injection was discovered in /coreframe/app/admin/pay/admin/index.php in WUZHI CMS 4.1.0 via the index.php?m=pay&f=index&v=listing keyValue parameter.

  • CVE-2018-15893CriAug 27, 2018
    risk 0.64cvss 9.8epss 0.02

    A SQL injection was discovered in /coreframe/app/admin/copyfrom.php in WUZHI CMS 4.1.0 via the index.php?m=core&f=copyfrom&v=listing keywords parameter.

  • CVE-2018-14515CriJul 23, 2018
    risk 0.64cvss 9.8epss 0.02

    A SQL injection was discovered in WUZHI CMS 4.1.0 that allows remote attackers to inject a malicious SQL statement via the index.php?m=promote&f=index&v=search keywords parameter.

  • CVE-2018-16350MedSep 2, 2018
    risk 0.40cvss 6.1epss 0.01

    WUZHI CMS 4.1.0 has XSS via the index.php?m=core&f=set&v=basic form[statcode] parameter.

  • CVE-2018-16349MedSep 2, 2018
    risk 0.40cvss 6.1epss 0.01

    WUZHI CMS 4.1.0 has XSS via the index.php?m=link&f=index&v=add form[remark] parameter.

  • CVE-2018-14513MedJul 23, 2018
    risk 0.40cvss 6.1epss 0.01

    An XSS vulnerability was discovered in WUZHI CMS 4.1.0. There is persistent XSS that allows remote attackers to inject arbitrary web script or HTML via the form[content] parameter to the index.php?m=feedback&f=index&v=contact URI.

  • CVE-2018-18939MedNov 5, 2018
    risk 0.31cvss 4.8epss 0.01

    An issue was discovered in WUZHI CMS 4.1.0. There is stored XSS in index.php?m=core&f=index via a seventh input field.