Show filters
150 Total Results
Displaying 1-10 of 150
Sort by:
Attacker Value
Moderate
CVE-2019-9053
Disclosure Date: March 26, 2019 (last updated November 27, 2024)
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve unauthenticated blind time-based SQL injection via the m1_idlist parameter.
3
Attacker Value
Unknown
CVE-2024-1529
Disclosure Date: March 12, 2024 (last updated April 01, 2024)
Vulnerability in CMS Made Simple 2.2.14, which does not sufficiently encode user-controlled input, resulting in a Cross-Site Scripting (XSS) vulnerability through /admin/adduser.php, in multiple parameters. This vulnerability could allow a remote attacker to send a specially crafted JavaScript payload to an authenticated user and partially take over their browser session.
0
Attacker Value
Unknown
CVE-2024-1528
Disclosure Date: March 12, 2024 (last updated April 01, 2024)
CMS Made Simple version 2.2.14, does not sufficiently encode user-controlled input, resulting in a Cross-Site Scripting (XSS) vulnerability through /admin/moduleinterface.php, in multiple parameters. This vulnerability could allow a remote attacker to send a specially crafted JavaScript payload to an authenticated user and partially hijack their browser session.
0
Attacker Value
Unknown
CVE-2024-1527
Disclosure Date: March 12, 2024 (last updated April 01, 2024)
Unrestricted file upload vulnerability in CMS Made Simple, affecting version 2.2.14. This vulnerability allows an authenticated user to bypass the security measures of the upload functionality and potentially create a remote execution of commands via webshell.
0
Attacker Value
Unknown
CVE-2023-43352
Disclosure Date: October 26, 2023 (last updated November 08, 2023)
An issue in CMSmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a crafted payload to the Content Manager Menu component.
0
Attacker Value
Unknown
CVE-2023-43360
Disclosure Date: October 25, 2023 (last updated October 31, 2023)
Cross Site Scripting vulnerability in CMSmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a crafted script to the Top Directory parameter in the File Picker Menu component.
0
Attacker Value
Unknown
CVE-2023-43358
Disclosure Date: October 23, 2023 (last updated October 30, 2023)
Cross Site Scripting vulnerability in CMSmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a crafted script to the Title parameter in the News Menu component.
0
Attacker Value
Unknown
CVE-2023-43357
Disclosure Date: October 20, 2023 (last updated October 25, 2023)
Cross Site Scripting vulnerability in CMSmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a crafted script to the Title parameter in the Manage Shortcuts component.
0
Attacker Value
Unknown
CVE-2023-43356
Disclosure Date: October 20, 2023 (last updated October 25, 2023)
Cross Site Scripting vulnerability in CMSmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a crafted script to the Global Meatadata parameter in the Global Settings Menu component.
0
Attacker Value
Unknown
CVE-2023-43355
Disclosure Date: October 20, 2023 (last updated October 25, 2023)
Cross Site Scripting vulnerability in CMSmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a crafted script to the password and password again parameters in the My Preferences - Add user component.
0