Show filters
150 Total Results
Displaying 51-60 of 150
Sort by:
Attacker Value
Unknown

CVE-2019-17226

Disclosure Date: October 06, 2019 (last updated November 27, 2024)
CMS Made Simple (CMSMS) 2.2.11 allows XSS via the Site Admin > Module Manager > Search Term field.
Attacker Value
Unknown

CVE-2019-11226

Disclosure Date: June 05, 2019 (last updated November 27, 2024)
CMS Made Simple 2.2.10 has XSS via the m1_name parameter in "Add Article" under Content -> Content Manager -> News.
0
Attacker Value
Unknown

CVE-2019-11513

Disclosure Date: April 25, 2019 (last updated November 27, 2024)
The File Manager in CMS Made Simple through 2.2.10 has Reflected XSS via the "New name" field in a Rename action.
0
Attacker Value
Unknown

CVE-2019-9056

Disclosure Date: April 11, 2019 (last updated November 27, 2024)
An issue was discovered in CMS Made Simple 2.2.8. In the module FrontEndUsers (in the file class.FrontEndUsersManipulate.php or class.FrontEndUsersManipulator.php), it is possible to reach an unserialize call with an untrusted __FEU__ cookie, and achieve authenticated object injection.
0
Attacker Value
Unknown

CVE-2019-10107

Disclosure Date: March 26, 2019 (last updated November 27, 2024)
CMS Made Simple 2.2.10 has XSS via the myaccount.php "Email Address" field, which is reachable via the "My Preferences -> My Account" section.
0
Attacker Value
Unknown

CVE-2019-10105

Disclosure Date: March 26, 2019 (last updated November 27, 2024)
CMS Made Simple 2.2.10 has a Self-XSS vulnerability via the Layout Design Manager "Name" field, which is reachable via a "Create a new Template" action to the Design Manager.
0
Attacker Value
Unknown

CVE-2019-10106

Disclosure Date: March 26, 2019 (last updated November 27, 2024)
CMS Made Simple 2.2.10 has XSS via the 'moduleinterface.php' Name field, which is reachable via an "Add Category" action to the "Site Admin Settings - News module" section.
0
Attacker Value
Unknown

CVE-2019-9059

Disclosure Date: March 26, 2019 (last updated November 27, 2024)
An issue was discovered in CMS Made Simple 2.2.8. It is possible, with an administrator account, to achieve command injection by modifying the path of the e-mail executable in Mail Settings, setting "sendmail" in the "Mailer" option, and launching the "Forgot your password" feature.
0
Attacker Value
Unknown

CVE-2019-9055

Disclosure Date: March 26, 2019 (last updated November 27, 2024)
An issue was discovered in CMS Made Simple 2.2.8. In the module DesignManager (in the files action.admin_bulk_css.php and action.admin_bulk_template.php), with an unprivileged user with Designer permission, it is possible reach an unserialize call with a crafted value in the m1_allparms parameter, and achieve object injection.
0
Attacker Value
Unknown

CVE-2019-9058

Disclosure Date: March 26, 2019 (last updated November 27, 2024)
An issue was discovered in CMS Made Simple 2.2.8. In the administrator page admin/changegroupperm.php, it is possible to send a crafted value in the sel_groups parameter that leads to authenticated object injection.