Show filters
27 Total Results
Displaying 1-10 of 27
Sort by:
Attacker Value
Unknown

CVE-2018-19465

Disclosure Date: June 07, 2019 (last updated November 27, 2024)
Maccms through 8.0 allows XSS via the site_keywords field to index.php?m=system-config because of tpl/module/system.php and tpl/html/system_config.html, related to template/paody/html/vod_index.html.
1
Attacker Value
Unknown

CVE-2022-47872

Disclosure Date: February 01, 2023 (last updated March 08, 2024)
A Server-Side Request Forgery (SSRF) in maccms10 v2021.1000.2000 allows attackers to force the application to make arbitrary requests via a crafted payload injected into the Name parameter under the Interface address module.
Attacker Value
Unknown

CVE-2022-44870

Disclosure Date: January 06, 2023 (last updated October 08, 2023)
A reflected cross-site scripting (XSS) vulnerability in maccms10 v2022.1000.3032 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter under the AD Management module.
Attacker Value
Unknown

CVE-2022-35148

Disclosure Date: August 17, 2022 (last updated October 08, 2023)
maccms10 v2021.1000.1081 to v2022.1000.3031 was discovered to contain a SQL injection vulnerability via the table parameter at database/columns.html.
Attacker Value
Unknown

CVE-2022-31303

Disclosure Date: June 21, 2022 (last updated October 07, 2023)
maccms10 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Server Group text field.
Attacker Value
Unknown

CVE-2022-31302

Disclosure Date: June 21, 2022 (last updated October 07, 2023)
maccms8 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Server Group text field.
Attacker Value
Unknown

CVE-2021-43707

Disclosure Date: March 31, 2022 (last updated October 07, 2023)
Cross Site Scripting (XSS) vulnerability exists in Maccms v10 via link_Name parameter.
Attacker Value
Unknown

CVE-2022-27887

Disclosure Date: March 25, 2022 (last updated October 07, 2023)
Maccms v10 was discovered to contain a reflected cross-site scripting (XSS) vulnerability in /admin.php/admin/vod/data.html via the repeat parameter.
Attacker Value
Unknown

CVE-2022-27886

Disclosure Date: March 25, 2022 (last updated October 07, 2023)
Maccms v10 was discovered to contain a reflected cross-site scripting (XSS) vulnerability in /admin.php/admin/ulog/index.html via the wd parameter.
Attacker Value
Unknown

CVE-2022-27885

Disclosure Date: March 25, 2022 (last updated October 07, 2023)
Maccms v10 was discovered to contain multiple reflected cross-site scripting (XSS) vulnerabilities in /admin.php/admin/website/data.html via the select and input parameters.