Show filters
150 Total Results
Displaying 61-70 of 150
Sort by:
Attacker Value
Unknown

CVE-2019-9061

Disclosure Date: March 26, 2019 (last updated November 27, 2024)
An issue was discovered in CMS Made Simple 2.2.8. In the module ModuleManager (in the file action.installmodule.php), it is possible to reach an unserialize call with untrusted input and achieve authenticated object injection by using the "install module" feature.
Attacker Value
Unknown

CVE-2019-9057

Disclosure Date: March 26, 2019 (last updated November 27, 2024)
An issue was discovered in CMS Made Simple 2.2.8. In the module FilePicker, it is possible to reach an unserialize call with an untrusted parameter, and achieve authenticated object injection.
Attacker Value
Unknown

CVE-2019-10017

Disclosure Date: March 24, 2019 (last updated November 27, 2024)
CMS Made Simple 2.2.10 has XSS via the moduleinterface.php Name field, which is reachable via an "Add a new Profile" action to the File Picker.
0
Attacker Value
Unknown

CVE-2019-9693 - CMS Made Simple (CMSMS) SQL Injection

Disclosure Date: March 11, 2019 (last updated November 27, 2024)
In CMS Made Simple (CMSMS) before 2.2.10, an authenticated user can achieve SQL Injection in class.showtime2_data.php via the functions _updateshow (parameter show_id), _inputshow (parameter show_id), _Getshowinfo (parameter show_id), _Getpictureinfo (parameter picture_id), _AdjustNameSeq (parameter shownumber), _Updatepicture (parameter picture_id), and _Deletepicture (parameter picture_id).
0
Attacker Value
Unknown

CVE-2018-20464

Disclosure Date: December 25, 2018 (last updated November 27, 2024)
There is a reflected XSS vulnerability in the CMS Made Simple 2.2.8 admin/myaccount.php. This vulnerability is triggered upon an attempt to modify a user's mailbox with the wrong format. The response contains the user's previously entered email address.
0
Attacker Value
Unknown

CVE-2018-19597

Disclosure Date: December 19, 2018 (last updated November 27, 2024)
CMS Made Simple 2.2.8 allows XSS via an uploaded SVG document, a related issue to CVE-2017-16798.
0
Attacker Value
Unknown

CVE-2018-18270

Disclosure Date: October 12, 2018 (last updated November 27, 2024)
XSS exists in CMS Made Simple version 2.2.7 via the m1_news_url parameter in an admin/moduleinterface.php "Content-->News-->Add Article" action.
0
Attacker Value
Unknown

CVE-2018-18271

Disclosure Date: October 12, 2018 (last updated November 27, 2024)
XSS exists in CMS Made Simple version 2.2.7 via the m1_extra parameter in an admin/moduleinterface.php "Content-->News-->Add Article" action.
0
Attacker Value
Unknown

CVE-2018-10518

Disclosure Date: April 27, 2018 (last updated November 26, 2024)
In CMS Made Simple (CMSMS) through 2.2.7, the "file delete" operation in the admin dashboard contains an arbitrary file deletion vulnerability that can cause DoS, exploitable by an admin user, because the attacker can remove all lib/ files in all directories.
0
Attacker Value
Unknown

CVE-2018-10515

Disclosure Date: April 27, 2018 (last updated November 26, 2024)
In CMS Made Simple (CMSMS) through 2.2.7, the "file unpack" operation in the admin dashboard contains a remote code execution vulnerability exploitable by an admin user because a .php file can be present in the extracted ZIP archive.
0