Export CSV

Products

1 vendor
VendorProductsCVEsKEVAvg EPSSWorst Severity
17035.7%CRITICAL

Related CVEs

7
CVE IDDescriptionSeverityCVSSKEVEPSSPublished
CVE-2025-1557A vulnerability, which was classified as problematic, was found in OFCMS 1.1.3. Affected is an unknown function. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.MEDIUM5.318.6%Feb 22, 2025
CVE-2024-48236An issue in ofcms 1.1.2 allows a remote attacker to execute arbitrary code via the FileOutputStream function in the write String method of the ofcms-admin\src\main\java\com\ofsoft\cms\core\uitle\FileUtils.java fileMEDIUM6.549.4%Oct 25, 2024
CVE-2024-48235An issue in ofcms 1.1.2 allows a remote attacker to execute arbitrary code via the save method of the TemplateController.java file.MEDIUM6.549.4%Oct 25, 2024
CVE-2024-9411A vulnerability classified as problematic has been found in OFCMS 1.1.2. This affects the function add of the file /admin/system/dict/add.json?sqlid=system.dict.save. The manipulation of the argument dict_value leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.MEDIUM5.325.6%Oct 1, 2024
CVE-2024-34256OFCMS V1.1.2 is vulnerable to SQL Injection via the new table function.CRITICAL9.8May 14, 2024
CVE-2023-51807Cross Site Scripting vulnerability in OFCMS v.1.14 allows a remote attacker to obtain sensitive information via a crafted payload to the title addition component.MEDIUM5.4Jan 16, 2024
CVE-2023-24760An issue found in Ofcms v.1.1.4 allows a remote attacker to to escalate privileges via the respwd method in SysUserController.HIGH8.8Mar 16, 2023