VYPR

Cmsmadesimple

by Cmsmadesimple

Source repositories

CVEs (156)

  • CVE-2020-22842MedSep 30, 2020
    risk 0.35cvss 5.4epss 0.01

    CMS Made Simple before 2.2.15 allows XSS via the m1_mod parameter in a ModuleManager local_uninstall action to admin/moduleinterface.php.

  • CVE-2020-14926MedJun 19, 2020
    risk 0.35cvss 5.4epss 0.01

    CMS Made Simple 2.2.14 allows XSS via a Search Term to the admin/moduleinterface.php?mact=ModuleManager page.

  • CVE-2020-10681MedMar 20, 2020
    risk 0.35cvss 5.4epss 0.01

    The Filemanager in CMS Made Simple 2.2.13 has stored XSS via a .pxd file, as demonstrated by m1_files[] to admin/moduleinterface.php.

  • CVE-2019-11226MedJun 5, 2019
    risk 0.35cvss 5.4epss 0.01

    CMS Made Simple 2.2.10 has XSS via the m1_name parameter in "Add Article" under Content -> Content Manager -> News.

  • CVE-2019-10107MedMar 26, 2019
    risk 0.35cvss 5.4epss 0.01

    CMS Made Simple 2.2.10 has XSS via the myaccount.php "Email Address" field, which is reachable via the "My Preferences -> My Account" section.

  • CVE-2019-10106MedMar 26, 2019
    risk 0.35cvss 5.4epss 0.01

    CMS Made Simple 2.2.10 has XSS via the 'moduleinterface.php' Name field, which is reachable via an "Add Category" action to the "Site Admin Settings - News module" section.

  • CVE-2019-10105MedMar 26, 2019
    risk 0.35cvss 5.4epss 0.01

    CMS Made Simple 2.2.10 has a Self-XSS vulnerability via the Layout Design Manager "Name" field, which is reachable via a "Create a new Template" action to the Design Manager.

  • CVE-2019-10017MedMar 24, 2019
    risk 0.35cvss 5.4epss 0.01

    CMS Made Simple 2.2.10 has XSS via the moduleinterface.php Name field, which is reachable via an "Add a new Profile" action to the File Picker.

  • CVE-2018-10523MedApr 27, 2018
    risk 0.35cvss 5.3epss 0.01

    CMS Made Simple (CMSMS) through 2.2.7 contains a physical path leakage Vulnerability via /modules/DesignManager/action.ajax_get_templates.php, /modules/DesignManager/action.ajax_get_stylesheets.php, /modules/FileManager/dunzip.php, or /modules/FileManager/untgz.php.

  • CVE-2018-9921MedApr 23, 2018
    risk 0.35cvss 5.3epss 0.01

    In CMS Made Simple 2.2.7, a Directory Traversal issue makes it possible to determine the existence of files and directories outside the web-site installation directory, and determine whether a file has contents matching a specified checksum. The attack uses an…

  • CVE-2018-10082MedApr 13, 2018
    risk 0.35cvss 5.3epss 0.01

    CMS Made Simple (CMSMS) through 2.2.7 allows physical path leakage via an invalid /index.php?page= value, a crafted URI starting with /index.php?mact=Search, or a direct request to /admin/header.php, /admin/footer.php, /lib/tasks/class.ClearCache.task.php, or…

  • CVE-2017-16799MedNov 12, 2017
    risk 0.35cvss 5.4epss 0.00

    In CMS Made Simple 2.2.3.1, in modules/New/action.addcategory.php, stored XSS is possible via the m1_name parameter to admin/moduleinterface.php during addition of a category, a related issue to CVE-2010-3882.

  • CVE-2017-16798MedNov 12, 2017
    risk 0.35cvss 5.4epss 0.01

    In CMS Made Simple 2.2.3.1, the is_file_acceptable function in modules/FileManager/action.upload.php only blocks file extensions that begin or end with a "php" substring, which allows remote attackers to bypass intended access restrictions or trigger XSS via other extensions, as…

  • CVE-2017-7257MedMar 24, 2017
    risk 0.35cvss 5.4epss 0.01

    XSS exists in the CMS Made Simple (CMSMS) 2.1.6 "Content-->News-->Add Article" feature via the m1_content parameter. Someone must login to conduct the attack.

  • CVE-2017-7256MedMar 24, 2017
    risk 0.35cvss 5.4epss 0.01

    XSS exists in the CMS Made Simple (CMSMS) 2.1.6 "Content-->News-->Add Article" feature via the m1_summary parameter. Someone must login to conduct the attack.

  • CVE-2017-7255MedMar 24, 2017
    risk 0.35cvss 5.4epss 0.01

    XSS exists in the CMS Made Simple (CMSMS) 2.1.6 "Content-->News-->Add Article" feature via the m1_title parameter. Someone must login to conduct the attack.

  • CVE-2017-6556MedMar 9, 2017
    risk 0.35cvss 5.4epss 0.01

    Cross-site scripting (XSS) vulnerability in CMS Made Simple (CMSMS) 2.1.6 allows remote authenticated users to inject arbitrary web script or HTML via the "adminpage > sitesetting > General Settings > globalmetadata" field.

  • CVE-2017-6555MedMar 9, 2017
    risk 0.35cvss 5.4epss 0.01

    Cross-site scripting (XSS) vulnerability in /admin/moduleinterface.php in CMS Made Simple 2.1.6 allows remote authenticated users to inject arbitrary web script or HTML via the m1_description parameter (aka "Design Manager > Categories > Category Description").

  • CVE-2017-6072MedFeb 21, 2017
    risk 0.35cvss 5.3epss 0.02

    CMS Made Simple version 1.x Form Builder before version 0.8.1.6 allows remote attackers to conduct information-disclosure attacks via defaultadmin.

  • CVE-2017-6071MedFeb 21, 2017
    risk 0.35cvss 5.3epss 0.02

    CMS Made Simple version 1.x Form Builder before version 0.8.1.6 allows remote attackers to conduct information-disclosure attacks via exportxml.

Page 5 of 8