JaliosCVEs & Vulnerabilities
2 CVEs affecting Jalios products, tracked from the National Vulnerability Database, with CVSS/EPSS scores and exploitation status.
2 CVEs→ All vendors
Most Affected Products
jcms 2
CVE-2020-15497MEDIUM
jcore/portal/ajaxPortal.jsp in Jalios JCMS 10.0.2 build-20200224104759 allows XSS via the types parameter. Note: It is asserted that this vulnerability is not present in the standard installation of Jalios JCMS
17 Jul 2020
6.1
CVSS
CVE-2019-19033CRITICAL
Jalios JCMS 10 allows attackers to access any part of the website and the WebDAV server with administrative privileges via a backdoor account, by using any username and the hardcoded dev password.
21 Nov 2019
9.8
CVSS
← PrevPage 1 / 1Next →