NuGet package
sscms
pkg:nuget/sscms
Vulnerabilities (5)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2023-2862 | Low | 3.5 | <= 7.2.1 | — | May 24, 2023 | A vulnerability, which was classified as problematic, was found in SiteServer CMS up to 7.2.1. Affected is an unknown function of the file /api/stl/actions/search. The manipulation of the argument ajaxDivId leads to cross site scripting. It is possible to launch the attack remote | |
| CVE-2022-30349 | Med | 6.1 | — | — | Jun 2, 2022 | siteserver SSCMS 6.15.51 is vulnerable to Cross Site Scripting (XSS). | |
| CVE-2021-42656 | Med | 5.4 | <= 6.15.51 | — | May 24, 2022 | SiteServer CMS V6.15.51 is affected by a Cross Site Scripting (XSS) vulnerability. | |
| CVE-2021-42655 | Hig | 8.8 | <= 6.15.51 | — | May 24, 2022 | SiteServer CMS V6.15.51 is affected by a SQL injection vulnerability. | |
| CVE-2019-11401 | Hig | 7.2 | < 6.12 | 6.12 | Apr 22, 2019 | A issue was discovered in SiteServer CMS 6.9.0. It allows remote attackers to execute arbitrary code because an administrator can add the permitted file extension .aassp, which is converted to .asp because the "as" substring is deleted. |
- affected <= 7.2.1
A vulnerability, which was classified as problematic, was found in SiteServer CMS up to 7.2.1. Affected is an unknown function of the file /api/stl/actions/search. The manipulation of the argument ajaxDivId leads to cross site scripting. It is possible to launch the attack remote
siteserver SSCMS 6.15.51 is vulnerable to Cross Site Scripting (XSS).
- affected <= 6.15.51
SiteServer CMS V6.15.51 is affected by a Cross Site Scripting (XSS) vulnerability.
- affected <= 6.15.51
SiteServer CMS V6.15.51 is affected by a SQL injection vulnerability.
- affected < 6.12fixed 6.12
A issue was discovered in SiteServer CMS 6.9.0. It allows remote attackers to execute arbitrary code because an administrator can add the permitted file extension .aassp, which is converted to .asp because the "as" substring is deleted.