Joyplus
Joyplus Project · 3 CVEs
CVE-2019-16655
HIGH
joyplus-cms 1.6.0 allows reinstallation if the install/ URI remains available.
Sep 21, 2019
CVE-2019-16656
CRITICAL
joyplus-cms 1.6.0 allows remote attackers to execute arbitrary PHP code via /install by placing the code in the name of…
Sep 21, 2019
CVE-2019-16660
HIGH
joyplus-cms 1.6.0 has admin_ajax.php?action=savexml&tab=vodplay CSRF.
Sep 21, 2019
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2019-16655 | joyplus-cms 1.6.0 allows reinstallation if the install/ URI remains available. | HIGH | 0.84% | Sep 21, 2019 |
| CVE-2019-16656 | joyplus-cms 1.6.0 allows remote attackers to execute arbitrary PHP code via /install by placing the code in the name of an object in the database. | CRITICAL | 1.33% | Sep 21, 2019 |
| CVE-2019-16660 | joyplus-cms 1.6.0 has admin_ajax.php?action=savexml&tab=vodplay CSRF. | HIGH | 0.55% | Sep 21, 2019 |
Showing 1 to 3 of 3 CVEs