Show filters
2 Total Results
Displaying 1-2 of 2
Sort by:
Attacker Value
Unknown

CVE-2020-21238

Disclosure Date: December 27, 2021 (last updated February 23, 2025)
An issue in the user login box of CSCMS v4.0 allows attackers to hijack user accounts via brute force attacks.
Attacker Value
Unknown

CVE-2018-16448

Disclosure Date: September 04, 2018 (last updated November 27, 2024)
Cscms 4 allows CSRF for creating a member via upload/admin.php/user/save, authenticating vip members via upload/admin.php/user/init/tid and upload/admin.php/user/init/rzid, and creating a super administrator and web editor via upload/admin.php/sys/save.
0