Ofcms Project
Ofcms Project Ofcms: vulnerabilidades y CVE
Ofcms Project Ofcms tiene 20 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE20
Últimos 12 meses0
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-1557 | Media (5.3) | 0.29% | — | 22 feb 2025 | A vulnerability, which was classified as problematic, was found in OFCMS 1.1.3. Affected is an unknown function. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely. The… |
| CVE-2024-48236 | Media (6.5) | 0.73% | — | 25 oct 2024 | An issue in ofcms 1.1.2 allows a remote attacker to execute arbitrary code via the FileOutputStream function in the write String method of the ofcms-admin\src\main\java\com\ofsoft\cms\core\uitle\FileUtils.java file |
| CVE-2024-48235 | Media (6.5) | 0.73% | — | 25 oct 2024 | An issue in ofcms 1.1.2 allows a remote attacker to execute arbitrary code via the save method of the TemplateController.java file. |
| CVE-2024-9411 | Media (5.3) | 0.37% | — | 1 oct 2024 | A vulnerability classified as problematic has been found in OFCMS 1.1.2. This affects the function add of the file /admin/system/dict/add.json?sqlid=system.dict.save. The manipulation of the argument dict_value leads to… |
| CVE-2024-34256 | Crítica (9.8) | 0.65% | — | 14 may 2024 | OFCMS V1.1.2 is vulnerable to SQL Injection via the new table function. |
| CVE-2023-51807 | Media (5.4) | 0.45% | — | 16 ene 2024 | Cross Site Scripting vulnerability in OFCMS v.1.14 allows a remote attacker to obtain sensitive information via a crafted payload to the title addition component. |
| CVE-2023-24760 | Alta (8.8) | 0.84% | — | 16 mar 2023 | An issue found in Ofcms v.1.1.4 allows a remote attacker to to escalate privileges via the respwd method in SysUserController. |
| CVE-2022-29653 | Media (6.1) | 0.57% | — | 2 jun 2022 | OFCMS v1.1.4 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /admin/comn/service/update.json. |
| CVE-2022-27961 | Media (5.4) | 0.44% | — | 10 abr 2022 | A cross-site scripting (XSS) vulnerability at /ofcms/company-c-47 in OFCMS v1.1.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Comment text box. |
| CVE-2022-27960 | Media (5.4) | 0.47% | — | 10 abr 2022 | Insecure permissions configured in the user_id parameter at SysUserController.java of OFCMS v1.1.4 allows attackers to access and arbitrarily modify users' personal information. |
| CVE-2019-9617 | Alta (8.8) | 2.7% | — | 6 mar 2019 | An issue was discovered in OFCMS before 1.1.3. Remote attackers can execute arbitrary code because blocking of .jsp and .jspx files does not consider (for example) file.jsp::$DATA to the admin/ueditor/uploadFile URI. |
| CVE-2019-9616 | Alta (7.2) | 2.7% | — | 6 mar 2019 | An issue was discovered in OFCMS before 1.1.3. Remote attackers can execute arbitrary code because blocking of .jsp and .jspx files does not consider (for example) file.jsp::$DATA to the admin/ueditor/uploadScrawl URI. |
| CVE-2019-9615 | Alta (7.2) | 1.3% | — | 6 mar 2019 | An issue was discovered in OFCMS before 1.1.3. It allows admin/system/generate/create?sql= SQL injection, related to SystemGenerateController.java. |
| CVE-2019-9614 | Alta (8.8) | 2.6% | — | 6 mar 2019 | An issue was discovered in OFCMS before 1.1.3. A command execution vulnerability exists via a template file with '<#assign ex="freemarker.template.utility.Execute"?new()> ${ ex("' followed by the command. |
| CVE-2019-9613 | Alta (7.2) | 2.7% | — | 6 mar 2019 | An issue was discovered in OFCMS before 1.1.3. Remote attackers can execute arbitrary code because blocking of .jsp and .jspx files does not consider (for example) file.jsp::$DATA to the admin/ueditor/uploadVideo URI. |
| CVE-2019-9612 | Alta (8.8) | 2.7% | — | 6 mar 2019 | An issue was discovered in OFCMS before 1.1.3. Remote attackers can execute arbitrary code because blocking of .jsp and .jspx files does not consider (for example) file.jsp::$DATA to the admin/comn/service/upload URI. |
| CVE-2019-9611 | Media (6.5) | 1.4% | — | 6 mar 2019 | An issue was discovered in OFCMS before 1.1.3. It allows admin/cms/template/getTemplates.html?res_path=res directory traversal, with ../ in the dir parameter, to write arbitrary content (in the file_content parameter)… |
| CVE-2019-9610 | Media (4.3) | 1.4% | — | 6 mar 2019 | An issue was discovered in OFCMS before 1.1.3. It has admin/cms/template/getTemplates.html?res_path=res&up_dir=../ directory traversal, related to the getTemplates function in TemplateController.java. |
| CVE-2019-9609 | Alta (8.8) | 2.7% | — | 6 mar 2019 | An issue was discovered in OFCMS before 1.1.3. Remote attackers can execute arbitrary code because blocking of .jsp and .jspx files does not consider (for example) file.jsp::$DATA to the… |
| CVE-2019-9608 | Alta (8.8) | 2.7% | — | 6 mar 2019 | An issue was discovered in OFCMS before 1.1.3. Remote attackers can execute arbitrary code because blocking of .jsp and .jspx files does not consider (for example) file.jsp::$DATA to the admin/ueditor/uploadImage URI. |