tp5cms through 2017-05-25 has XSS via the admin.php/article/index.html q parameter.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| tp5cms_project | tp5cms | * |
tp5cms through 2017-05-25 has CSRF via admin.php/category/delete.html.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| tp5cms_project | tp5cms | * |