LiveActive security incident?Get immediate response
CVE archive

June 2020

Browse CVE records published in June 2020, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 1976 matching CVEs · Page 13 of 40.

Unknown · CVSS Not scored

CVE-2020-21005: WellCMS 2.0 beta3 is vulnerable to File Upload.

WellCMS 2.0 beta3 is vulnerable to File Upload. A user can log in to the CMS background and upload a picture. Because the upload file type is controllable, the user can modify the upload file type to get webshell.

Published Jun 3, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2020-20473: White Shark System (WSS) 1.3.2 has a SQL injection vulnerability.

White Shark System (WSS) 1.3.2 has a SQL injection vulnerability. The vulnerability stems from the control_task.php, control_project.php, default_user.php files failing to filter the sort parameter. Remote attackers can exploit the vulnerability to obtain database sensitive information.

Published Jun 21, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2020-20474: White Shark System (WSS) 1.3.2 has a SQL injection vulnerability.

White Shark System (WSS) 1.3.2 has a SQL injection vulnerability. The vulnerability stems from the default_task_edituser.php files failing to filter the csa_to_user parameter. Remote attackers can exploit the vulnerability to obtain database sensitive information.

Published Jun 21, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2020-19202: An authenticated Stored XSS (Cross-site Scripting) exists in the "captive.cgi" Captive Portal via the "Titl...

An authenticated Stored XSS (Cross-site Scripting) exists in the "captive.cgi" Captive Portal via the "Title of Login Page" text box or "TITLE" parameter in IPFire 2.21 (x86_64) - Core Update 130. It allows an authenticated WebGUI user with privileges to execute Stored Cross-site Scripting in the Captive Portal page.

Published Jun 17, 2021 · Updated Aug 4, 2024