Cmsmadesimple

Cms Made Simple

155 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 62.56%
  • Veröffentlicht 06.07.2023 15:15:15
  • Zuletzt bearbeitet 21.11.2024 08:10:59

CMS Made Simple v2.2.17 is vulnerable to Remote Command Execution via the File Upload Function.

Exploit
  • EPSS 0.34%
  • Veröffentlicht 08.05.2023 14:15:10
  • Zuletzt bearbeitet 29.01.2025 15:15:10

File upload vulnerability in CMS Made Simple through 2.2.15 allows remote authenticated attackers to gain a webshell via a crafted phar file.

Exploit
  • EPSS 0.19%
  • Veröffentlicht 08.05.2023 14:15:10
  • Zuletzt bearbeitet 29.01.2025 17:15:13

SQL Injection vulnerability in CMS Made Simple through 2.2.15 allows remote attackers to execute arbitrary commands via the m1_sortby parameter to modules/News/function.admin_articlestab.php.

Exploit
  • EPSS 1.32%
  • Veröffentlicht 09.06.2022 15:15:09
  • Zuletzt bearbeitet 21.11.2024 06:25:09

CMS Made Simple <=2.2.15 is affected by SQL injection in modules/News/function.admin_articlestab.php. The $sortby variable is concatenated with $query1, but it is possible to inject arbitrary SQL language without using the '.

  • EPSS 0.33%
  • Veröffentlicht 13.04.2022 23:15:07
  • Zuletzt bearbeitet 21.11.2024 06:28:44

Cross Site Scripting (XSS) vulnerability exists in CMS Made Simple 2.2.15 via the Name field in an Add Category action in moduleinterface.php.

Exploit
  • EPSS 6.43%
  • Veröffentlicht 28.02.2022 23:15:12
  • Zuletzt bearbeitet 21.11.2024 06:49:26

CMS Made Simple v2.2.15 was discovered to contain a Remote Command Execution (RCE) vulnerability via the upload avatar function. This vulnerability is exploited via a crafted image file.

Exploit
  • EPSS 0.49%
  • Veröffentlicht 28.02.2022 23:15:12
  • Zuletzt bearbeitet 21.11.2024 06:49:26

CMS Made Simple v2.2.15 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the parameter m1_fmmessage.

Exploit
  • EPSS 0.28%
  • Veröffentlicht 22.09.2021 20:15:08
  • Zuletzt bearbeitet 21.11.2024 05:13:49

CMS Made Simple 2.2.14 was discovered to contain a cross-site scripting (XSS) vulnerability which allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the Field Definition text field.

  • EPSS 0.42%
  • Veröffentlicht 17.09.2021 16:15:07
  • Zuletzt bearbeitet 21.11.2024 04:50:54

An issue was discovered in CMS Made Simple 2.2.8. It is possible to achieve unauthenticated path traversal in the CGExtensions module (in the file action.setdefaulttemplate.php) with the m1_filename parameter; and through the action.showmessage.php f...

  • EPSS 0.32%
  • Veröffentlicht 05.08.2021 17:15:07
  • Zuletzt bearbeitet 21.11.2024 05:13:23

CMS Made Simple (CMSMS) 2.2.14 allows stored XSS via the Extensions > Fie Picker..