Vulnerabilities (CVE)

Filtered by vendor Kordil Edms Project Subscribe
Filtered by product Kordil Edms
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-13888 1 Kordil Edms Project 1 Kordil Edms 2024-11-21 3.5 LOW 5.4 MEDIUM
Kordil EDMS through 2.2.60rc3 allows stored XSS in users_edit.php, users_management_edit.php, and user_management.php.
CVE-2020-13887 1 Kordil Edms Project 1 Kordil Edms 2024-11-21 6.5 MEDIUM 8.8 HIGH
documents_add.php in Kordil EDMS through 2.2.60rc3 allows Remote Command Execution because .php files can be uploaded to the documents folder.