VYPR

Cscms

by Cscms

CVEs (2)

  • CVE-2018-16730Sep 8, 2018
    risk 0.00cvss epss 0.00

    \upload\plugins\sys\Install.php in CScms 4.1 has XSS via the site name.

  • CVE-2018-11527May 29, 2018
    risk 0.00cvss epss 0.00

    An issue was discovered in CScms v4.1. A Cross-site request forgery (CSRF) vulnerability in plugins/sys/admin/Sys.php allows remote attackers to change the administrator's username and password via /admin.php/sys/editpass_save.