Show filters
31 Total Results
Displaying 1-10 of 31
Sort by:
Attacker Value
Unknown
CVE-2024-9282
Disclosure Date: September 27, 2024 (last updated October 05, 2024)
A vulnerability was found in bg5sbk MiniCMS 1.11. It has been classified as problematic. Affected is an unknown function of the file page-edit.php. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The initial researcher advisory mentions confusing version and file name information. The vendor was contacted early about this disclosure but did not respond in any way.
0
Attacker Value
Unknown
CVE-2024-9281
Disclosure Date: September 27, 2024 (last updated October 05, 2024)
A vulnerability was found in bg5sbk MiniCMS up to 1.11 and classified as problematic. This issue affects some unknown processing of the file post-edit.php. The manipulation leads to cross-site request forgery. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The initial researcher advisory mentions confusing version and file name information. The vendor was contacted early about this disclosure but did not respond in any way.
0
Attacker Value
Unknown
CVE-2023-46378
Disclosure Date: October 31, 2023 (last updated November 09, 2023)
Stored Cross Site Scripting (XSS) vulnerability in MiniCMS 1.1.1 allows attackers to run arbitrary code via crafted string appended to /mc-admin/conf.php.
0
Attacker Value
Unknown
CVE-2021-33387
Disclosure Date: February 24, 2023 (last updated October 08, 2023)
Cross Site Scripting Vulnerability in MiniCMS v.1.10 allows attacker to execute arbitrary code via a crafted get request.
0
Attacker Value
Unknown
CVE-2020-19896
Disclosure Date: June 28, 2022 (last updated February 24, 2025)
File inclusion vulnerability in Minicms v1.9 allows remote attackers to execute arbitary PHP code via post-edit.php.
0
Attacker Value
Unknown
CVE-2022-33121
Disclosure Date: June 24, 2022 (last updated February 24, 2025)
A Cross-Site Request Forgery (CSRF) in MiniCMS v1.11 allows attackers to arbitrarily delete local .dat files via clicking on a malicious link.
0
Attacker Value
Unknown
CVE-2021-41663
Disclosure Date: June 13, 2022 (last updated February 23, 2025)
A cross-site scripting (XSS) vulnerability exists in Mini CMS V1.11. The vulnerability exists in the article upload: post-edit.php page.
0
Attacker Value
Unknown
CVE-2021-44970
Disclosure Date: February 10, 2022 (last updated February 23, 2025)
MiniCMS v1.11 was discovered to contain a cross-site scripting (XSS) vulnerability via /mc-admin/page-edit.php.
0
Attacker Value
Unknown
CVE-2020-17999
Disclosure Date: April 28, 2021 (last updated February 22, 2025)
Cross Site Scripting (XSS) in MiniCMS v1.10 allows remote attackers to execute arbitrary code by injecting commands via a crafted HTTP request to the component "/mc-admin/post-edit.php".
0
Attacker Value
Unknown
CVE-2020-36051
Disclosure Date: January 05, 2021 (last updated February 22, 2025)
Directory traversal vulnerability in page_edit.php in MiniCMS V1.10 allows remote attackers to read arbitrary files via the state parameter.
0