VendorsEarclinkespcms-p8all versions
Vulnerabilities

Earclink ESPCMS-P8

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2019-5488
EARCLINK ESPCMS-P8 has SQL injection in the install_pack/index.php?ac=Member&at=verifyAccount verify_key parameter. install_pack/espcms_public/espcms_db.php may allow retrieving sensitive information from the ESPCMS database.
Published 2019-01-07 · Modified
7.5EPSS 0.012
CVE-2020-20125
EARCLINK ESPCMS-P8 contains a cross-site scripting (XSS) vulnerability in espcms_web\espcms_load.php.
Published 2021-09-28 · Modified
6.1EPSS 0.007