Rain Cold

2 exploits Active since Oct 2023
CVE-2023-43905 WRITEUP HIGH WRITEUP
writercms 1.1.0 - Insufficiently Protected Credentials
Incorrect access control in writercms v1.1.0 allows attackers to directly obtain backend account passwords via unspecified vectors.
CVSS 7.5
CVE-2023-43906 WRITEUP MEDIUM WRITEUP
Xolo CMS 0.11 - Reflected Cross-Site Scripting
Xolo CMS v0.11 was discovered to contain a reflected cross-site scripting (XSS) vulnerability.
CVSS 6.1