Total
4 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2020-12472 | 1 Mono | 1 Monox | 2024-02-28 | 3.5 LOW | 5.4 MEDIUM |
MonoX through 5.1.40.5152 allows stored XSS via User Status, Blog Comments, or Blog Description. | |||||
CVE-2020-12473 | 1 Mono | 1 Monox | 2024-02-28 | 9.0 HIGH | 7.2 HIGH |
MonoX through 5.1.40.5152 allows admins to execute arbitrary programs by reconfiguring the Converter Executable setting from ffmpeg.exe to a different program. | |||||
CVE-2020-12471 | 1 Mono | 1 Monox | 2024-02-28 | 7.5 HIGH | 9.8 CRITICAL |
MonoX through 5.1.40.5152 allows remote code execution via HTML5Upload.ashx or Pages/SocialNetworking/lng/en-US/PhotoGallery.aspx because of deserialization in ModuleGallery.HTML5Upload, ModuleGallery.SilverLightUploadModule, HTML5Upload, and SilverLightUploadHandler. | |||||
CVE-2020-12470 | 1 Mono | 1 Monox | 2024-02-28 | 6.5 MEDIUM | 7.2 HIGH |
MonoX through 5.1.40.5152 allows administrators to execute arbitrary code by modifying an ASPX template. |