VYPR

NuGet package

sscms

pkg:nuget/sscms

Vulnerabilities (5)

  • CVE-2023-2862LowMay 24, 2023
    affected <= 7.2.1

    A vulnerability, which was classified as problematic, was found in SiteServer CMS up to 7.2.1. Affected is an unknown function of the file /api/stl/actions/search. The manipulation of the argument ajaxDivId leads to cross site scripting. It is possible to launch the attack remote

  • CVE-2022-30349MedJun 2, 2022

    siteserver SSCMS 6.15.51 is vulnerable to Cross Site Scripting (XSS).

  • CVE-2021-42656MedMay 24, 2022
    affected <= 6.15.51

    SiteServer CMS V6.15.51 is affected by a Cross Site Scripting (XSS) vulnerability.

  • CVE-2021-42655HigMay 24, 2022
    affected <= 6.15.51

    SiteServer CMS V6.15.51 is affected by a SQL injection vulnerability.

  • CVE-2019-11401HigApr 22, 2019
    affected < 6.12fixed 6.12

    A issue was discovered in SiteServer CMS 6.9.0. It allows remote attackers to execute arbitrary code because an administrator can add the permitted file extension .aassp, which is converted to .asp because the "as" substring is deleted.