Gitee Exploits

415 exploits tracked across all sources.

Sort: Activity Stars
CVE-2019-7684 GITEE CRITICAL java
inxedu <2018-12-24 - Code Injection
inxedu through 2018-12-24 has a vulnerability that can lead to the upload of a malicious JSP file. The vulnerable code location is com.inxedu.os.common.controller.VideoUploadController#gok4 (com/inxedu/os/common/controller/VideoUploadController.java). The attacker uses the /video/uploadvideo fileType parameter to change the list of acceptable extensions from jpg,gif,png,jpeg to jpg,gif,png,jsp,jpeg.
by inxeduopen
1,602 stars
CVSS 9.8
CVE-2020-21152 GITEE CRITICAL java
Inxedu - SQL Injection
SQL Injection vulnerability in inxedu 2.0.6 allows attackers to execute arbitrary commands via the functionIds parameter to /saverolefunction.
by inxeduopen
1,602 stars
CVSS 9.8
CVE-2020-35326 GITEE CRITICAL java
Inxedu - SQL Injection
SQL Injection vulnerability in file /inxedu/demo_inxedu_open/src/main/resources/mybatis/inxedu/website/WebsiteImagesMapper.xml in inxedu 2.0.6 via the id value.
by inxeduopen
1,602 stars
CVSS 9.8
CVE-2020-35430 GITEE CRITICAL java
Inxedu - SQL Injection
SQL Injection in com/inxedu/OS/edu/controller/letter/AdminMsgSystemController in Inxedu v2.0.6 via the ids parameter to admin/letter/delsystem.
by inxeduopen
1,602 stars
CVSS 9.8
CVE-2022-4353 GITEE LOW java
LinZhaoguan pb-cms 2.0 - XSS
A vulnerability has been found in LinZhaoguan pb-cms 2.0 and classified as problematic. Affected by this vulnerability is the function IpUtil.getIpAddr. The manipulation leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-215113 was assigned to this vulnerability.
by LinZhaoguan
1,410 stars
CVSS 3.5
CVE-2022-4354 GITEE MEDIUM java
LinZhaoguan pb-cms 2.0 - XSS
A vulnerability was found in LinZhaoguan pb-cms 2.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /blog/comment of the component Message Board. The manipulation leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-215114 is the identifier assigned to this vulnerability.
by LinZhaoguan
1,410 stars
CVSS 4.3
CVE-2024-10477 GITEE LOW java
Pb-cms < 2.0.1 - XSS
A vulnerability classified as problematic was found in LinZhaoguan pb-cms up to 2.0.1. This vulnerability affects unknown code of the file /admin#permissions of the component Permission Management Page. The manipulation leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
by LinZhaoguan
1,410 stars
CVSS 2.4
CVE-2024-10478 GITEE LOW java
Pb-cms < 2.0.1 - XSS
A vulnerability, which was classified as problematic, has been found in LinZhaoguan pb-cms up to 2.0.1. This issue affects some unknown processing of the file /admin#article/edit?id=2 of the component Edit Article Handler. The manipulation leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
by LinZhaoguan
1,410 stars
CVSS 2.4
CVE-2024-10479 GITEE LOW java
Pb-cms < 2.0.1 - XSS
A vulnerability, which was classified as problematic, was found in LinZhaoguan pb-cms up to 2.0.1. Affected is an unknown function of the file /admin#themes of the component Theme Management Module. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
by LinZhaoguan
1,410 stars
CVSS 2.4
CVE-2023-2862 GITEE LOW c#
SiteServer CMS <7.2.1 - XSS
A vulnerability, which was classified as problematic, was found in SiteServer CMS up to 7.2.1. Affected is an unknown function of the file /api/stl/actions/search. The manipulation of the argument ajaxDivId leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. VDB-229818 is the identifier assigned to this vulnerability.
by siteserver
1,291 stars
CVSS 3.5
CVE-2022-27960 GITEE MEDIUM java
Ofcms - Incorrect Default Permissions
Insecure permissions configured in the user_id parameter at SysUserController.java of OFCMS v1.1.4 allows attackers to access and arbitrarily modify users' personal information.
by oufu
1,025 stars
CVSS 5.4
CVE-2022-27961 GITEE MEDIUM java
Ofcms - XSS
A cross-site scripting (XSS) vulnerability at /ofcms/company-c-47 in OFCMS v1.1.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Comment text box.
by oufu
1,025 stars
CVSS 5.4
CVE-2022-29653 GITEE MEDIUM java
Ofcms - XSS
OFCMS v1.1.4 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /admin/comn/service/update.json.
by oufu
1,025 stars
CVSS 6.1
CVE-2023-24760 GITEE HIGH java
Ofcms <1.1.4 - Privilege Escalation
An issue found in Ofcms v.1.1.4 allows a remote attacker to to escalate privileges via the respwd method in SysUserController.
by oufu
1,025 stars
CVSS 8.8
CVE-2023-24760 GITEE HIGH java
Ofcms <1.1.4 - Privilege Escalation
An issue found in Ofcms v.1.1.4 allows a remote attacker to to escalate privileges via the respwd method in SysUserController.
by oufu
1,025 stars
CVSS 8.8
CVE-2023-51807 GITEE MEDIUM java
OFCMS 1.14 - XSS
Cross Site Scripting vulnerability in OFCMS v.1.14 allows a remote attacker to obtain sensitive information via a crafted payload to the title addition component.
by oufu
1,025 stars
CVSS 5.4
CVE-2023-3058 GITEE LOW php
07FLY CRM <1.2.0 - XSS
A vulnerability was found in 07FLY CRM up to 1.2.0. It has been declared as problematic. This vulnerability affects unknown code of the component User Profile Handler. The manipulation leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-230560.
by 07fly
958 stars
CVSS 3.5
CVE-2021-40910 GITEE MEDIUM php
PHPCMS <9.6.3 - XSS
There is a reflective cross-site scripting (XSS) vulnerability in the PHPCMS V9.6.3 management side.
by phpcms
663 stars
CVSS 6.1
CVE-2023-30331 GITEE CRITICAL java
beetl <3.15.0 - Code Injection
An issue in the render function of beetl v3.15.0 allows attackers to execute server-side template injection (SSTI) via a crafted payload.
by xiandafu
643 stars
CVSS 9.8
CVE-2024-22533 GITEE CRITICAL java
Before Beetl <3.15.12 - Code Injection
Before Beetl v3.15.12, the rendering template has a server-side template injection (SSTI) vulnerability. When the incoming template is controllable, it will be filtered by the DefaultNativeSecurityManager blacklist. Because blacklist filtering is not strict, the blacklist can be bypassed, leading to arbitrary code execution.
by xiandafu
643 stars
CVSS 9.8
CVE-2023-1937 GITEE MEDIUM java
zhenfeng13 My-Blog - CSRF
A vulnerability, which was classified as problematic, was found in zhenfeng13 My-Blog. Affected is an unknown function of the file /admin/configurations/userInfo. The manipulation of the argument yourAvatar/yourName/yourEmail leads to cross-site request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The identifier of this vulnerability is VDB-225264.
by zhenfeng13
631 stars
CVSS 4.3
CVE-2023-27093 GITEE MEDIUM java
My-Blog - XSS
Cross Site Scripting vulnerability found in My-Blog allows attackers to cause a denial of service via the Post function.
by zhenfeng13
631 stars
CVSS 6.1
CVE-2023-46393 GITEE HIGH php
gougucms v4.08.18 - Auth Bypass
gougucms v4.08.18 was discovered to contain a password reset poisoning vulnerability which allows attackers to arbitrarily reset users' passwords via a crafted packet.
by gougufree
619 stars
CVSS 7.5
CVE-2023-46394 GITEE MEDIUM php
gougucms <4.08.18 - XSS
A stored cross-site scripting (XSS) vulnerability in /home/user/edit_submit of gougucms v4.08.18 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the headimgurl parameter.
by gougufree
619 stars
CVSS 5.4
CVE-2023-7226 GITEE MEDIUM java
meetyoucrop big-whale 1.1 - Improper Ownership Management
A vulnerability was found in meetyoucrop big-whale 1.1 and classified as critical. Affected by this issue is some unknown functionality of the file /auth/user/all.api of the component Admin Module. The manipulation of the argument id leads to improper ownership management. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-250232.
by progr1mmer
596 stars
CVSS 6.3