CVE-2020-36415
- EPSS 0.28%
- Veröffentlicht 02.07.2021 18:15:08
- Zuletzt bearbeitet 21.11.2024 05:29:27
A stored cross scripting (XSS) vulnerability in CMS Made Simple 2.2.14 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "Create a new Stylesheet" parameter under the "Stylesheets" module.
CVE-2020-27377
- EPSS 0.31%
- Veröffentlicht 01.06.2021 15:15:07
- Zuletzt bearbeitet 21.11.2024 05:21:06
A cross-site scripting (XSS) vulnerability was discovered in the Administrator panel on the 'Setting News' module on CMS Made Simple 2.2.14 which allows an attacker to execute arbitrary web scripts.
CVE-2021-28935
- EPSS 0.23%
- Veröffentlicht 30.03.2021 12:16:11
- Zuletzt bearbeitet 21.11.2024 06:00:24
CMS Made Simple (CMSMS) 2.2.15 allows authenticated XSS via the /admin/addbookmark.php script through the Site Admin > My Preferences > Title field.
CVE-2020-20138
- EPSS 0.33%
- Veröffentlicht 17.12.2020 23:15:13
- Zuletzt bearbeitet 21.11.2024 05:11:52
Cross Site Scripting (XSS) vulnerability in the Showtime2 Slideshow module in CMS Made Simple (CMSMS) 2.2.4.
CVE-2020-24860
- EPSS 0.63%
- Veröffentlicht 01.10.2020 14:15:15
- Zuletzt bearbeitet 21.11.2024 05:16:08
CMS Made Simple 2.2.14 allows an authenticated user with access to the Content Manager to edit content and put persistent XSS payload in the affected text fields. The user can get cookies from every authenticated user who visits the website.
CVE-2020-22842
- EPSS 0.37%
- Veröffentlicht 30.09.2020 18:15:24
- Zuletzt bearbeitet 21.11.2024 05:13:26
CMS Made Simple before 2.2.15 allows XSS via the m1_mod parameter in a ModuleManager local_uninstall action to admin/moduleinterface.php.
CVE-2020-17462
- EPSS 0.44%
- Veröffentlicht 14.08.2020 15:15:13
- Zuletzt bearbeitet 21.11.2024 05:08:09
CMS Made Simple 2.2.14 allows Authenticated Arbitrary File Upload because the File Manager does not block .ptar files, a related issue to CVE-2017-16798.
CVE-2020-14926
- EPSS 0.3%
- Veröffentlicht 19.06.2020 17:15:18
- Zuletzt bearbeitet 21.11.2024 05:04:26
CMS Made Simple 2.2.14 allows XSS via a Search Term to the admin/moduleinterface.php?mact=ModuleManager page.
CVE-2020-13660
- EPSS 0.31%
- Veröffentlicht 28.05.2020 19:15:11
- Zuletzt bearbeitet 21.11.2024 05:01:42
CMS Made Simple through 2.2.14 allows XSS via a crafted File Picker profile name.
CVE-2020-10682
- EPSS 1.86%
- Veröffentlicht 20.03.2020 04:15:16
- Zuletzt bearbeitet 21.11.2024 04:55:50
The Filemanager in CMS Made Simple 2.2.13 allows remote code execution via a .php.jpegd JPEG file, as demonstrated by m1_files[] to admin/moduleinterface.php. The file should be sent as application/octet-stream and contain PHP code (it need not be a ...