CVE-2022-4377
- EPSS 0.2%
- Veröffentlicht 09.12.2022 08:15:10
- Zuletzt bearbeitet 21.11.2024 07:35:09
A vulnerability was found in S-CMS 5.0 Build 20220328. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component Contact Information Page. The manipulation of the argument Make a Call leads to cr...
CVE-2022-23336
- EPSS 0.26%
- Veröffentlicht 14.02.2022 21:15:09
- Zuletzt bearbeitet 21.11.2024 06:48:25
S-CMS v5.0 was discovered to contain a SQL injection vulnerability in member_pay.php via the O_id parameter.
CVE-2020-20426
- EPSS 0.41%
- Veröffentlicht 22.12.2021 23:15:07
- Zuletzt bearbeitet 21.11.2024 05:12:04
S-CMS Government Station Building System v5.0 contains a cross-site scripting (XSS) vulnerability in /function/booksave.php.
CVE-2020-20425
- EPSS 0.41%
- Veröffentlicht 22.12.2021 23:15:07
- Zuletzt bearbeitet 21.11.2024 05:12:03
S-CMS Government Station Building System v5.0 contains a cross-site scripting (XSS) vulnerability in the search function.
CVE-2020-19954
- EPSS 0.44%
- Veröffentlicht 14.10.2021 15:15:08
- Zuletzt bearbeitet 21.11.2024 05:09:30
An XML External Entity (XXE) vulnerability was discovered in /api/notify.php in S-CMS 3.0 which allows attackers to read arbitrary files.
CVE-2020-19158
- EPSS 0.3%
- Veröffentlicht 15.09.2021 14:15:08
- Zuletzt bearbeitet 21.11.2024 05:08:59
Cross Site Scripting (XSS) in S-CMS build 20191014 and earlier allows remote attackers to execute arbitrary code via the 'Site Title' parameter of the component '/data/admin/#/app/config/'.
CVE-2020-20340
- EPSS 0.24%
- Veröffentlicht 01.09.2021 20:15:07
- Zuletzt bearbeitet 21.11.2024 05:12:01
A SQL injection vulnerability in the 4.edu.php\conn\function.php component of S-CMS v1.0 allows attackers to access sensitive database information.
CVE-2020-19046
- EPSS 0.32%
- Veröffentlicht 31.08.2021 14:15:25
- Zuletzt bearbeitet 21.11.2024 05:08:55
Cross Site Scripting (XSS) in S-CMS v1.0 allows remote attackers to execute arbitrary code via the component '/admin/tpl.php?page='.
CVE-2020-20699
- EPSS 0.29%
- Veröffentlicht 30.07.2021 14:15:13
- Zuletzt bearbeitet 21.11.2024 05:12:14
A cross site scripting (XSS) vulnerability in S-CMS PHP v3.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the Copyright text box under Basic Settings.
CVE-2020-20701
- EPSS 0.32%
- Veröffentlicht 30.07.2021 14:15:13
- Zuletzt bearbeitet 21.11.2024 05:12:14
A stored cross site scripting (XSS) vulnerability in /app/config/of S-CMS PHP v3.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.