CVE-2020-23243
Published Jul 26, 2021Cross Site Scripting (XSS) vulnerability in NavigateCMS NavigateCMS 2.9 via the name="wrong_path_redirect" feature.
Vendor/product archive
12 CVEs tagged to naviwebs / navigatecms — 6 Critical, 0 High, 6 Medium, 0 Low, 0 Unrated.
Cross Site Scripting (XSS) vulnerability in NavigateCMS NavigateCMS 2.9 via the name="wrong_path_redirect" feature.
Cross Site Scripting (XSS) vulnerability in NavigateCMS 2.9 when performing a Create or Edit via the Tools feature.
In NavigateCMS version 2.9.4 and below, function `block` is vulnerable to sql injection on parameter `block-order`, which results in arbitrary sql query execution in the backend d…
In NavigateCMS version 2.9.4 and below, function in `structure.php` is vulnerable to sql injection on parameter `children_order`, which results in arbitrary sql query execution in…
In NavigateCMS version 2.9.4 and below, function in `product.php` is vulnerable to sql injection on parameter `id` through a post request, which results in arbitrary sql query exe…
In NavigateCMS version 2.9.4 and below, function in `templates.php` is vulnerable to sql injection on parameter `template-properties-order`, which results in arbitrary sql query e…
In NavigateCMS version 2.9.4 and below, function in `product.php` is vulnerable to sql injection on parameter `products-order` through a post request, which results in arbitrary s…
NavigateCMS 2.9 is affected by Cross Site Scripting (XSS) on module "Configuration."
NavigateCMS 2.9 is affected by Cross Site Scripting (XSS) on module "Content."
NavigateCMS 2.9 is affected by Cross Site Scripting (XSS) on module "Configuration."
NavigateCMS 2.9 is affected by Cross Site Scripting (XSS) via the module "Shop."
The install_from_hash functionality in Navigate CMS 2.9 does not consider the .phtml extension when examining files within a ZIP archive that may contain PHP code, in check_upload…