VYPR
Unrated severityNVD Advisory· Published Feb 19, 2015· Updated Jun 17, 2026

CVE-2015-1603

CVE-2015-1603

Description

Multiple cross-site scripting (XSS) vulnerabilities in Adminsystems CMS before 4.0.2 allow remote attackers to inject arbitrary web script or HTML via the (1) page parameter to index.php or (2) id parameter in a users_users action to asys/site/system.php.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • Adminsystems CMS Project/CMSllm-create2 versions
    <4.0.2+ 1 more
    • (no CPE)range: <4.0.2
    • cpe:2.3:a:adminsystems_cms_project:adminsystems_cms:*:*:*:*:*:*:*:*range: <=4.0.0

Patches

Vulnerability mechanics

References

10

News mentions

0

No linked articles in our index yet.