VYPR

Cmsms

by Cmsmadesimple

CVEs (6)

  • CVE-2017-17735CriDec 18, 2017
    risk 0.64cvss 9.8epss 0.01

    CMS Made Simple (CMSMS) before 2.2.5 does not properly cache login information in cookies.

  • CVE-2018-10519HigApr 27, 2018
    risk 0.57cvss 8.8epss 0.01

    CMS Made Simple (CMSMS) 2.2.7 contains a privilege escalation vulnerability from ordinary user to admin user by arranging for the eff_uid value within $_COOKIE[$this->_loginkey] to equal 1, because files in the tmp/ directory are accessible through HTTP requests. NOTE: this…

  • CVE-2018-10082MedApr 13, 2018
    risk 0.35cvss 5.3epss 0.01

    CMS Made Simple (CMSMS) through 2.2.7 allows physical path leakage via an invalid /index.php?page= value, a crafted URI starting with /index.php?mact=Search, or a direct request to /admin/header.php, /admin/footer.php, /lib/tasks/class.ClearCache.task.php, or…

  • CVE-2018-10032MedApr 11, 2018
    risk 0.31cvss 4.8epss 0.01

    CMS Made Simple (aka CMSMS) 2.2.7 has Reflected XSS in admin/moduleinterface.php via the m1_version parameter.

  • CVE-2018-7893MedMar 12, 2018
    risk 0.31cvss 4.8epss 0.01

    CMS Made Simple (CMSMS) 2.2.6 has stored XSS in admin/moduleinterface.php via the metadata parameter.

  • CVE-2018-5964MedJan 25, 2018
    risk 0.31cvss 4.8epss 0.01

    CMS Made Simple (CMSMS) 2.2.5 has XSS in admin/moduleinterface.php via the m1_messages parameter.