Show filters
150 Total Results
Displaying 41-50 of 150
Sort by:
Attacker Value
Unknown
CVE-2020-24860
Disclosure Date: October 01, 2020 (last updated February 22, 2025)
CMS Made Simple 2.2.14 allows an authenticated user with access to the Content Manager to edit content and put persistent XSS payload in the affected text fields. The user can get cookies from every authenticated user who visits the website.
0
Attacker Value
Unknown
CVE-2020-22842
Disclosure Date: September 30, 2020 (last updated February 22, 2025)
CMS Made Simple before 2.2.15 allows XSS via the m1_mod parameter in a ModuleManager local_uninstall action to admin/moduleinterface.php.
0
Attacker Value
Unknown
CVE-2020-17462
Disclosure Date: August 14, 2020 (last updated February 21, 2025)
CMS Made Simple 2.2.14 allows Authenticated Arbitrary File Upload because the File Manager does not block .ptar files, a related issue to CVE-2017-16798.
0
Attacker Value
Unknown
CVE-2020-14926
Disclosure Date: June 19, 2020 (last updated February 21, 2025)
CMS Made Simple 2.2.14 allows XSS via a Search Term to the admin/moduleinterface.php?mact=ModuleManager page.
0
Attacker Value
Unknown
CVE-2020-13660
Disclosure Date: May 28, 2020 (last updated February 21, 2025)
CMS Made Simple through 2.2.14 allows XSS via a crafted File Picker profile name.
0
Attacker Value
Unknown
CVE-2020-10682
Disclosure Date: March 20, 2020 (last updated February 21, 2025)
The Filemanager in CMS Made Simple 2.2.13 allows remote code execution via a .php.jpegd JPEG file, as demonstrated by m1_files[] to admin/moduleinterface.php. The file should be sent as application/octet-stream and contain PHP code (it need not be a valid JPEG file).
0
Attacker Value
Unknown
CVE-2020-10681
Disclosure Date: March 20, 2020 (last updated February 21, 2025)
The Filemanager in CMS Made Simple 2.2.13 has stored XSS via a .pxd file, as demonstrated by m1_files[] to admin/moduleinterface.php.
0
Attacker Value
Unknown
CVE-2011-4310
Disclosure Date: November 26, 2019 (last updated November 27, 2024)
The news module in CMSMS before 1.9.4.3 allows remote attackers to corrupt new articles.
0
Attacker Value
Unknown
CVE-2019-17629
Disclosure Date: October 16, 2019 (last updated November 27, 2024)
CMS Made Simple (CMSMS) 2.2.11 allows stored XSS by an admin via a crafted image filename on the "file manager > upload images" screen.
0
Attacker Value
Unknown
CVE-2019-17630
Disclosure Date: October 16, 2019 (last updated November 27, 2024)
CMS Made Simple (CMSMS) 2.2.11 allows stored XSS by an admin via a crafted image filename on the "News > Add Article" screen.
0