Show filters
19 Total Results
Displaying 1-10 of 19
Sort by:
Attacker Value
Unknown

CVE-2023-37785

Disclosure Date: July 13, 2023 (last updated October 08, 2023)
A cross-site scripting (XSS) vulnerability in ImpressCMS v1.4.5 and before allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the smile_code parameter of the component /editprofile.php.
Attacker Value
Unknown

CVE-2022-26986

Disclosure Date: April 05, 2022 (last updated February 23, 2025)
SQL Injection in ImpressCMS 1.4.3 and earlier allows remote attackers to inject into the code in unintended way, this allows an attacker to read and modify the sensitive information from the database used by the application. If misconfigured, an attacker can even upload a malicious web shell to compromise the entire system.
Attacker Value
Unknown

CVE-2021-26601

Disclosure Date: March 28, 2022 (last updated February 23, 2025)
ImpressCMS before 1.4.3 allows libraries/image-editor/image-edit.php image_temp Directory Traversal.
Attacker Value
Unknown

CVE-2021-26600

Disclosure Date: March 28, 2022 (last updated February 23, 2025)
ImpressCMS before 1.4.3 has plugins/preloads/autologin.php type confusion with resultant Authentication Bypass (!= instead of !==).
Attacker Value
Unknown

CVE-2021-26599

Disclosure Date: March 28, 2022 (last updated February 23, 2025)
ImpressCMS before 1.4.3 allows include/findusers.php groups SQL Injection.
Attacker Value
Unknown

CVE-2021-26598

Disclosure Date: March 28, 2022 (last updated February 23, 2025)
ImpressCMS before 1.4.3 has Incorrect Access Control because include/findusers.php allows access by unauthenticated attackers (who are, by design, able to have a security token).
Attacker Value
Unknown

CVE-2022-24977

Disclosure Date: February 14, 2022 (last updated February 23, 2025)
ImpressCMS before 1.4.2 allows unauthenticated remote code execution via ...../// directory traversal in origName or imageName, leading to unsafe interaction with the CKEditor processImage.php script. The payload may be placed in PHP_SESSION_UPLOAD_PROGRESS when the PHP installation supports upload_progress.
Attacker Value
Unknown

CVE-2021-28088

Disclosure Date: March 11, 2021 (last updated February 22, 2025)
Cross-site scripting (XSS) in modules/content/admin/content.php in ImpressCMS profile 1.4.2 allows remote attackers to inject arbitrary web script or HTML parameters through the "Display Name" field.
Attacker Value
Unknown

CVE-2020-17551

Disclosure Date: October 07, 2020 (last updated February 22, 2025)
ImpressCMS 1.4.0 is affected by XSS in modules/system/admin.php which may result in arbitrary remote code execution.
Attacker Value
Unknown

CVE-2018-13983

Disclosure Date: May 06, 2019 (last updated November 27, 2024)
ImpressCMS 1.3.10 has XSS via the PATH_INFO to htdocs/install/index.php, htdocs/install/page_langselect.php, or htdocs/install/page_modcheck.php.
0