Show filters
150 Total Results
Displaying 61-70 of 150
Sort by:
Attacker Value
Unknown
CVE-2019-9061
Disclosure Date: March 26, 2019 (last updated November 27, 2024)
An issue was discovered in CMS Made Simple 2.2.8. In the module ModuleManager (in the file action.installmodule.php), it is possible to reach an unserialize call with untrusted input and achieve authenticated object injection by using the "install module" feature.
0
Attacker Value
Unknown
CVE-2019-9057
Disclosure Date: March 26, 2019 (last updated November 27, 2024)
An issue was discovered in CMS Made Simple 2.2.8. In the module FilePicker, it is possible to reach an unserialize call with an untrusted parameter, and achieve authenticated object injection.
0
Attacker Value
Unknown
CVE-2019-10017
Disclosure Date: March 24, 2019 (last updated November 27, 2024)
CMS Made Simple 2.2.10 has XSS via the moduleinterface.php Name field, which is reachable via an "Add a new Profile" action to the File Picker.
0
Attacker Value
Unknown
CVE-2019-9693 - CMS Made Simple (CMSMS) SQL Injection
Disclosure Date: March 11, 2019 (last updated November 27, 2024)
In CMS Made Simple (CMSMS) before 2.2.10, an authenticated user can achieve SQL Injection in class.showtime2_data.php via the functions _updateshow (parameter show_id), _inputshow (parameter show_id), _Getshowinfo (parameter show_id), _Getpictureinfo (parameter picture_id), _AdjustNameSeq (parameter shownumber), _Updatepicture (parameter picture_id), and _Deletepicture (parameter picture_id).
0
Attacker Value
Unknown
CVE-2018-20464
Disclosure Date: December 25, 2018 (last updated November 27, 2024)
There is a reflected XSS vulnerability in the CMS Made Simple 2.2.8 admin/myaccount.php. This vulnerability is triggered upon an attempt to modify a user's mailbox with the wrong format. The response contains the user's previously entered email address.
0
Attacker Value
Unknown
CVE-2018-19597
Disclosure Date: December 19, 2018 (last updated November 27, 2024)
CMS Made Simple 2.2.8 allows XSS via an uploaded SVG document, a related issue to CVE-2017-16798.
0
Attacker Value
Unknown
CVE-2018-18270
Disclosure Date: October 12, 2018 (last updated November 27, 2024)
XSS exists in CMS Made Simple version 2.2.7 via the m1_news_url parameter in an admin/moduleinterface.php "Content-->News-->Add Article" action.
0
Attacker Value
Unknown
CVE-2018-18271
Disclosure Date: October 12, 2018 (last updated November 27, 2024)
XSS exists in CMS Made Simple version 2.2.7 via the m1_extra parameter in an admin/moduleinterface.php "Content-->News-->Add Article" action.
0
Attacker Value
Unknown
CVE-2018-10518
Disclosure Date: April 27, 2018 (last updated November 26, 2024)
In CMS Made Simple (CMSMS) through 2.2.7, the "file delete" operation in the admin dashboard contains an arbitrary file deletion vulnerability that can cause DoS, exploitable by an admin user, because the attacker can remove all lib/ files in all directories.
0
Attacker Value
Unknown
CVE-2018-10515
Disclosure Date: April 27, 2018 (last updated November 26, 2024)
In CMS Made Simple (CMSMS) through 2.2.7, the "file unpack" operation in the admin dashboard contains a remote code execution vulnerability exploitable by an admin user because a .php file can be present in the extracted ZIP archive.
0