VYPR

Cszcms

by Cszcms

CVEs (2)

  • CVE-2024-58307HigDec 11, 2025
    risk 0.57cvss 8.8epss 0.00

    CSZCMS 1.3.0 contains an authenticated SQL injection vulnerability in the members view functionality that allows authenticated attackers to manipulate database queries. Attackers can inject malicious SQL code through the view parameter to potentially execute time-based blind SQL…

  • CVE-2022-28997HigMay 23, 2022
    risk 0.49cvss 7.5epss 0.02

    CSZCMS v1.3.0 allows attackers to execute a Server-Side Request Forgery (SSRF) which can be leveraged to leak sensitive data via a local file inclusion at /admin/filemanager/connector/.