Mingsoft

Mcms

52 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.4%
  • Veröffentlicht 08.12.2022 10:15:11
  • Zuletzt bearbeitet 21.11.2024 07:35:06

A vulnerability, which was classified as problematic, was found in Mingsoft MCMS 5.2.8. Affected is an unknown function of the file search.do. The manipulation of the argument content_title leads to cross site scripting. It is possible to launch the ...

Exploit
  • EPSS 1.07%
  • Veröffentlicht 16.08.2022 13:15:11
  • Zuletzt bearbeitet 21.11.2024 07:13:22

Mingsoft MCMS 5.2.8 was discovered to contain a SQL injection vulnerability in /mdiy/model/delete URI via models Lists.

Exploit
  • EPSS 1.07%
  • Veröffentlicht 16.08.2022 13:15:11
  • Zuletzt bearbeitet 21.11.2024 07:12:41

Mingsoft MCMS 5.2.8 was discovered to contain a SQL injection vulnerability in /mdiy/page/verify URI via fieldName parameter.

Exploit
  • EPSS 1.51%
  • Veröffentlicht 01.07.2022 21:15:08
  • Zuletzt bearbeitet 21.11.2024 07:05:29

MCMS v5.2.8 was discovered to contain an arbitrary file upload vulnerability.

Exploit
  • EPSS 2.56%
  • Veröffentlicht 02.06.2022 14:15:53
  • Zuletzt bearbeitet 21.11.2024 07:02:50

An arbitrary file upload vulnerability was discovered in MCMS 5.2.7, allowing an attacker to execute arbitrary code through a crafted ZIP file.

Exploit
  • EPSS 0.65%
  • Veröffentlicht 02.06.2022 14:15:49
  • Zuletzt bearbeitet 21.11.2024 06:59:29

An issue was discovered in MCMS 5.2.7. There is a CSRF vulnerability that can add an administrator account via ms/basic/manager/save.do.

Exploit
  • EPSS 1.44%
  • Veröffentlicht 11.05.2022 18:15:29
  • Zuletzt bearbeitet 21.11.2024 07:02:07

Mingsoft MCMS 5.2.7 was discovered to contain a SQL injection vulnerability in /mdiy/dict/list URI via orderBy parameter.

Exploit
  • EPSS 1.44%
  • Veröffentlicht 11.05.2022 18:15:29
  • Zuletzt bearbeitet 21.11.2024 07:02:07

Mingsoft MCMS v5.2.7 was discovered to contain a SQL injection vulnerability in /mdiy/dict/listExcludeApp URI via orderBy parameter.

Exploit
  • EPSS 1.58%
  • Veröffentlicht 02.05.2022 14:15:07
  • Zuletzt bearbeitet 21.11.2024 06:55:46

MCMS v5.2.27 was discovered to contain a SQL injection vulnerability in the orderBy parameter at /dict/list.do.

Exploit
  • EPSS 0.66%
  • Veröffentlicht 22.04.2022 20:15:08
  • Zuletzt bearbeitet 21.11.2024 06:55:36

MCMS v5.2.7 contains a Cross-Site Request Forgery (CSRF) via /role/saveOrUpdateRole.do. This vulnerability allows attackers to escalate privileges and modify data.