CVE-2023-36969
- EPSS 62.56%
- Veröffentlicht 06.07.2023 15:15:15
- Zuletzt bearbeitet 21.11.2024 08:10:59
CMS Made Simple v2.2.17 is vulnerable to Remote Command Execution via the File Upload Function.
CVE-2021-28998
- EPSS 0.34%
- Veröffentlicht 08.05.2023 14:15:10
- Zuletzt bearbeitet 29.01.2025 15:15:10
File upload vulnerability in CMS Made Simple through 2.2.15 allows remote authenticated attackers to gain a webshell via a crafted phar file.
CVE-2021-28999
- EPSS 0.19%
- Veröffentlicht 08.05.2023 14:15:10
- Zuletzt bearbeitet 29.01.2025 17:15:13
SQL Injection vulnerability in CMS Made Simple through 2.2.15 allows remote attackers to execute arbitrary commands via the m1_sortby parameter to modules/News/function.admin_articlestab.php.
CVE-2021-40961
- EPSS 1.32%
- Veröffentlicht 09.06.2022 15:15:09
- Zuletzt bearbeitet 21.11.2024 06:25:09
CMS Made Simple <=2.2.15 is affected by SQL injection in modules/News/function.admin_articlestab.php. The $sortby variable is concatenated with $query1, but it is possible to inject arbitrary SQL language without using the '.
CVE-2021-43154
- EPSS 0.33%
- Veröffentlicht 13.04.2022 23:15:07
- Zuletzt bearbeitet 21.11.2024 06:28:44
Cross Site Scripting (XSS) vulnerability exists in CMS Made Simple 2.2.15 via the Name field in an Add Category action in moduleinterface.php.
CVE-2022-23906
- EPSS 6.43%
- Veröffentlicht 28.02.2022 23:15:12
- Zuletzt bearbeitet 21.11.2024 06:49:26
CMS Made Simple v2.2.15 was discovered to contain a Remote Command Execution (RCE) vulnerability via the upload avatar function. This vulnerability is exploited via a crafted image file.
CVE-2022-23907
- EPSS 0.49%
- Veröffentlicht 28.02.2022 23:15:12
- Zuletzt bearbeitet 21.11.2024 06:49:26
CMS Made Simple v2.2.15 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the parameter m1_fmmessage.
CVE-2020-23481
- EPSS 0.28%
- Veröffentlicht 22.09.2021 20:15:08
- Zuletzt bearbeitet 21.11.2024 05:13:49
CMS Made Simple 2.2.14 was discovered to contain a cross-site scripting (XSS) vulnerability which allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the Field Definition text field.
CVE-2019-9060
- EPSS 0.42%
- Veröffentlicht 17.09.2021 16:15:07
- Zuletzt bearbeitet 21.11.2024 04:50:54
An issue was discovered in CMS Made Simple 2.2.8. It is possible to achieve unauthenticated path traversal in the CGExtensions module (in the file action.setdefaulttemplate.php) with the m1_filename parameter; and through the action.showmessage.php f...
CVE-2020-22732
- EPSS 0.32%
- Veröffentlicht 05.08.2021 17:15:07
- Zuletzt bearbeitet 21.11.2024 05:13:23
CMS Made Simple (CMSMS) 2.2.14 allows stored XSS via the Extensions > Fie Picker..