Cmsmadesimple

Cms Made Simple

156 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.47%
  • Veröffentlicht 06.07.2023 15:15:16
  • Zuletzt bearbeitet 21.11.2024 08:10:59

A Cross-site scripting (XSS) vulnerability in CMS Made Simple v2.2.17 allows remote attackers to inject arbitrary web script or HTML via the File Upload function.

Exploit
  • EPSS 44.81%
  • Veröffentlicht 06.07.2023 15:15:15
  • Zuletzt bearbeitet 21.11.2024 08:10:59

CMS Made Simple v2.2.17 is vulnerable to Remote Command Execution via the File Upload Function.

Exploit
  • EPSS 1.29%
  • Veröffentlicht 08.05.2023 14:15:10
  • Zuletzt bearbeitet 29.01.2025 15:15:10

File upload vulnerability in CMS Made Simple through 2.2.15 allows remote authenticated attackers to gain a webshell via a crafted phar file.

Exploit
  • EPSS 1.33%
  • Veröffentlicht 08.05.2023 14:15:10
  • Zuletzt bearbeitet 29.01.2025 17:15:13

SQL Injection vulnerability in CMS Made Simple through 2.2.15 allows remote attackers to execute arbitrary commands via the m1_sortby parameter to modules/News/function.admin_articlestab.php.

Exploit
  • EPSS 1.64%
  • Veröffentlicht 09.06.2022 15:15:09
  • Zuletzt bearbeitet 21.11.2024 06:25:09

CMS Made Simple <=2.2.15 is affected by SQL injection in modules/News/function.admin_articlestab.php. The $sortby variable is concatenated with $query1, but it is possible to inject arbitrary SQL language without using the '.

  • EPSS 0.53%
  • Veröffentlicht 13.04.2022 23:15:07
  • Zuletzt bearbeitet 21.11.2024 06:28:44

Cross Site Scripting (XSS) vulnerability exists in CMS Made Simple 2.2.15 via the Name field in an Add Category action in moduleinterface.php.

Exploit
  • EPSS 2.09%
  • Veröffentlicht 28.02.2022 23:15:12
  • Zuletzt bearbeitet 21.11.2024 06:49:26

CMS Made Simple v2.2.15 was discovered to contain a Remote Command Execution (RCE) vulnerability via the upload avatar function. This vulnerability is exploited via a crafted image file.

Exploit
  • EPSS 0.63%
  • Veröffentlicht 28.02.2022 23:15:12
  • Zuletzt bearbeitet 21.11.2024 06:49:26

CMS Made Simple v2.2.15 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the parameter m1_fmmessage.

Exploit
  • EPSS 0.46%
  • Veröffentlicht 22.09.2021 20:15:08
  • Zuletzt bearbeitet 21.11.2024 05:13:49

CMS Made Simple 2.2.14 was discovered to contain a cross-site scripting (XSS) vulnerability which allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the Field Definition text field.

  • EPSS 1.47%
  • Veröffentlicht 17.09.2021 16:15:07
  • Zuletzt bearbeitet 21.11.2024 04:50:54

An issue was discovered in CMS Made Simple 2.2.8. It is possible to achieve unauthenticated path traversal in the CGExtensions module (in the file action.setdefaulttemplate.php) with the m1_filename parameter; and through the action.showmessage.php f...