361,800
Total CVEs
26,223
Critical
85,816
High
1,626
CISA KEV
0
This Week
14 results · Page 1/1
The comment editing template (dzz/comment/template/edit_form.htm) in DzzOffice 2.3.x lacks adequate security escaping for user-controllable data in multiple contexts, including HTML and JavaScript strings. This allows low-privilege attackers to construct comment content or request parameters and execute arbitrary JavaScript code when the victim opens the editing pop-up.
dzzoffice
DzzOffice v2.3.7 and before is vulnerable to Arbitrary File Upload in /dzz/system/ueditor/php/controller.php.
dzzoffice
DzzOffice v2.3.7 and before is vulnerable to SQL Injection in explorer/groupmanage.
dzzoffice
dzzoffice 2.02.1 is vulnerable to Directory Traversal via user/space/about.php.
dzzoffice