Show filters
150 Total Results
Displaying 51-60 of 150
Sort by:
Attacker Value
Unknown
CVE-2019-17226
Disclosure Date: October 06, 2019 (last updated November 27, 2024)
CMS Made Simple (CMSMS) 2.2.11 allows XSS via the Site Admin > Module Manager > Search Term field.
0
Attacker Value
Unknown
CVE-2019-11226
Disclosure Date: June 05, 2019 (last updated November 27, 2024)
CMS Made Simple 2.2.10 has XSS via the m1_name parameter in "Add Article" under Content -> Content Manager -> News.
0
Attacker Value
Unknown
CVE-2019-11513
Disclosure Date: April 25, 2019 (last updated November 27, 2024)
The File Manager in CMS Made Simple through 2.2.10 has Reflected XSS via the "New name" field in a Rename action.
0
Attacker Value
Unknown
CVE-2019-9056
Disclosure Date: April 11, 2019 (last updated November 27, 2024)
An issue was discovered in CMS Made Simple 2.2.8. In the module FrontEndUsers (in the file class.FrontEndUsersManipulate.php or class.FrontEndUsersManipulator.php), it is possible to reach an unserialize call with an untrusted __FEU__ cookie, and achieve authenticated object injection.
0
Attacker Value
Unknown
CVE-2019-10107
Disclosure Date: March 26, 2019 (last updated November 27, 2024)
CMS Made Simple 2.2.10 has XSS via the myaccount.php "Email Address" field, which is reachable via the "My Preferences -> My Account" section.
0
Attacker Value
Unknown
CVE-2019-10105
Disclosure Date: March 26, 2019 (last updated November 27, 2024)
CMS Made Simple 2.2.10 has a Self-XSS vulnerability via the Layout Design Manager "Name" field, which is reachable via a "Create a new Template" action to the Design Manager.
0
Attacker Value
Unknown
CVE-2019-10106
Disclosure Date: March 26, 2019 (last updated November 27, 2024)
CMS Made Simple 2.2.10 has XSS via the 'moduleinterface.php' Name field, which is reachable via an "Add Category" action to the "Site Admin Settings - News module" section.
0
Attacker Value
Unknown
CVE-2019-9059
Disclosure Date: March 26, 2019 (last updated November 27, 2024)
An issue was discovered in CMS Made Simple 2.2.8. It is possible, with an administrator account, to achieve command injection by modifying the path of the e-mail executable in Mail Settings, setting "sendmail" in the "Mailer" option, and launching the "Forgot your password" feature.
0
Attacker Value
Unknown
CVE-2019-9055
Disclosure Date: March 26, 2019 (last updated November 27, 2024)
An issue was discovered in CMS Made Simple 2.2.8. In the module DesignManager (in the files action.admin_bulk_css.php and action.admin_bulk_template.php), with an unprivileged user with Designer permission, it is possible reach an unserialize call with a crafted value in the m1_allparms parameter, and achieve object injection.
0
Attacker Value
Unknown
CVE-2019-9058
Disclosure Date: March 26, 2019 (last updated November 27, 2024)
An issue was discovered in CMS Made Simple 2.2.8. In the administrator page admin/changegroupperm.php, it is possible to send a crafted value in the sel_groups parameter that leads to authenticated object injection.
0