Chshcms

Mccms

11 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.09%
  • Veröffentlicht 21.08.2025 00:00:00
  • Zuletzt bearbeitet 24.09.2025 00:02:49

MCCMS 2.7.0 is vulnerable to Arbitrary file deletion in the Backups.php component. This allows an attacker to execute arbitrary commands

Exploit
  • EPSS 0.11%
  • Veröffentlicht 06.08.2025 15:15:32
  • Zuletzt bearbeitet 18.08.2025 15:38:30

MCCMS v2.7.0 has an SSRF vulnerability located in the index() method of the sys\apps\controllers\api\Gf.php file, where the pic parameter is processed. The pic parameter is decrypted using the sys_auth($pic, 1) function, which utilizes a hard-coded k...

Exploit
  • EPSS 0.04%
  • Veröffentlicht 14.07.2025 00:00:00
  • Zuletzt bearbeitet 17.07.2025 13:27:40

An authenticated arbitrary file download vulnerability in the component /admin/Backups.php of Mccms v2.7.0 allows attackers to download arbitrary files via a crafted GET request.

Exploit
  • EPSS 0.11%
  • Veröffentlicht 29.05.2025 21:00:06
  • Zuletzt bearbeitet 10.06.2025 15:14:10

A vulnerability was found in chshcms mccms 2.7. It has been declared as critical. This vulnerability affects the function restore_del of the file /sys/apps/controllers/admin/Backups.php. The manipulation of the argument dirs leads to path traversal. ...

Exploit
  • EPSS 0.1%
  • Veröffentlicht 29.05.2025 20:31:04
  • Zuletzt bearbeitet 10.06.2025 15:13:37

A vulnerability was found in chshcms mccms 2.7. It has been classified as critical. This affects the function index of the file sys/apps/controllers/api/Gf.php. The manipulation of the argument pic leads to server-side request forgery. It is possible...

Exploit
  • EPSS 0.03%
  • Veröffentlicht 17.09.2023 22:15:46
  • Zuletzt bearbeitet 21.11.2024 08:40:55

A vulnerability, which was classified as critical, was found in mccms 2.6. This affects an unknown part of the file /category/order/hits/copyright/46/finish/1/list/1. The manipulation with the input '"1 leads to sql injection. The exploit has been di...

Exploit
  • EPSS 0.06%
  • Veröffentlicht 14.06.2023 07:15:09
  • Zuletzt bearbeitet 21.11.2024 08:16:45

A vulnerability was found in mccms up to 2.6.5. It has been rated as critical. Affected by this issue is the function pic_api of the file sys/apps/controllers/admin/Comic.php. The manipulation of the argument url leads to server-side request forgery....

Exploit
  • EPSS 0.06%
  • Veröffentlicht 14.06.2023 07:15:09
  • Zuletzt bearbeitet 21.11.2024 08:16:45

A vulnerability classified as critical has been found in mccms up to 2.6.5. This affects the function pic_save of the file sys/apps/controllers/admin/Comic.php. The manipulation of the argument pic leads to server-side request forgery. It is possible...

Exploit
  • EPSS 0.34%
  • Veröffentlicht 28.04.2023 20:15:13
  • Zuletzt bearbeitet 31.01.2025 17:15:10

SQL injection vulnerability in mccms 2.6 allows remote attackers to run arbitrary SQL commands via Author Center ->Reader Comments ->Search.

Exploit
  • EPSS 0.31%
  • Veröffentlicht 28.04.2023 20:15:13
  • Zuletzt bearbeitet 31.01.2025 17:15:10

An issue discovered in mccms 2.6.1 allows remote attackers to cause a denial of service via Backend management interface ->System Configuration->Cache Configuration->Cache security characters.