Show filters
150 Total Results
Displaying 41-50 of 150
Sort by:
Attacker Value
Unknown

CVE-2020-24860

Disclosure Date: October 01, 2020 (last updated February 22, 2025)
CMS Made Simple 2.2.14 allows an authenticated user with access to the Content Manager to edit content and put persistent XSS payload in the affected text fields. The user can get cookies from every authenticated user who visits the website.
Attacker Value
Unknown

CVE-2020-22842

Disclosure Date: September 30, 2020 (last updated February 22, 2025)
CMS Made Simple before 2.2.15 allows XSS via the m1_mod parameter in a ModuleManager local_uninstall action to admin/moduleinterface.php.
Attacker Value
Unknown

CVE-2020-17462

Disclosure Date: August 14, 2020 (last updated February 21, 2025)
CMS Made Simple 2.2.14 allows Authenticated Arbitrary File Upload because the File Manager does not block .ptar files, a related issue to CVE-2017-16798.
Attacker Value
Unknown

CVE-2020-14926

Disclosure Date: June 19, 2020 (last updated February 21, 2025)
CMS Made Simple 2.2.14 allows XSS via a Search Term to the admin/moduleinterface.php?mact=ModuleManager page.
Attacker Value
Unknown

CVE-2020-13660

Disclosure Date: May 28, 2020 (last updated February 21, 2025)
CMS Made Simple through 2.2.14 allows XSS via a crafted File Picker profile name.
Attacker Value
Unknown

CVE-2020-10682

Disclosure Date: March 20, 2020 (last updated February 21, 2025)
The Filemanager in CMS Made Simple 2.2.13 allows remote code execution via a .php.jpegd JPEG file, as demonstrated by m1_files[] to admin/moduleinterface.php. The file should be sent as application/octet-stream and contain PHP code (it need not be a valid JPEG file).
Attacker Value
Unknown

CVE-2020-10681

Disclosure Date: March 20, 2020 (last updated February 21, 2025)
The Filemanager in CMS Made Simple 2.2.13 has stored XSS via a .pxd file, as demonstrated by m1_files[] to admin/moduleinterface.php.
Attacker Value
Unknown

CVE-2011-4310

Disclosure Date: November 26, 2019 (last updated November 27, 2024)
The news module in CMSMS before 1.9.4.3 allows remote attackers to corrupt new articles.
Attacker Value
Unknown

CVE-2019-17629

Disclosure Date: October 16, 2019 (last updated November 27, 2024)
CMS Made Simple (CMSMS) 2.2.11 allows stored XSS by an admin via a crafted image filename on the "file manager > upload images" screen.
Attacker Value
Unknown

CVE-2019-17630

Disclosure Date: October 16, 2019 (last updated November 27, 2024)
CMS Made Simple (CMSMS) 2.2.11 allows stored XSS by an admin via a crafted image filename on the "News > Add Article" screen.