VYPR

CMS

by Ilch

CVEs (2)

  • CVE-2014-1944Mar 9, 2014
    risk 0.03cvss epss 0.05

    Cross-site scripting (XSS) vulnerability in Ilch CMS 2.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the text parameter to index.php/guestbook/index/newentry.

  • CVE-2015-2083Feb 25, 2015
    risk 0.00cvss epss 0.00

    Cross-site request forgery (CSRF) vulnerability in Ilch CMS allows remote attackers to hijack the authentication of administrators for requests that add a value to a profile field via a profilefields request to admin.php.