Cmsms
CVEs (10)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2017-17735 | Cri | 0.64 | 9.8 | 0.01 | Dec 18, 2017 | CMS Made Simple (CMSMS) before 2.2.5 does not properly cache login information in cookies. | ||
| CVE-2018-10519 | Hig | 0.57 | 8.8 | 0.01 | Apr 27, 2018 | CMS Made Simple (CMSMS) 2.2.7 contains a privilege escalation vulnerability from ordinary user to admin user by arranging for the eff_uid value within $_COOKIE[$this->_loginkey] to equal 1, because files in the tmp/ directory are accessible through HTTP requests. NOTE: this… | ||
| CVE-2019-9692 | Med | 0.49 | 6.5 | 0.46 | Mar 11, 2019 | class.showtime2_image.php in CMS Made Simple (CMSMS) before 2.2.10 does not ensure that a watermark file has a standard image file extension (GIF, JPG, JPEG, or PNG). | ||
| CVE-2021-28935 | Med | 0.38 | 5.4 | 0.02 | Mar 30, 2021 | CMS Made Simple (CMSMS) 2.2.15 allows authenticated XSS via the /admin/addbookmark.php script through the Site Admin > My Preferences > Title field. | ||
| CVE-2018-10082 | Med | 0.35 | 5.3 | 0.01 | Apr 13, 2018 | CMS Made Simple (CMSMS) through 2.2.7 allows physical path leakage via an invalid /index.php?page= value, a crafted URI starting with /index.php?mact=Search, or a direct request to /admin/header.php, /admin/footer.php, /lib/tasks/class.ClearCache.task.php, or… | ||
| CVE-2019-17630 | Med | 0.31 | 4.8 | 0.01 | Oct 16, 2019 | CMS Made Simple (CMSMS) 2.2.11 allows stored XSS by an admin via a crafted image filename on the "News > Add Article" screen. | ||
| CVE-2019-17629 | Med | 0.31 | 4.8 | 0.01 | Oct 16, 2019 | CMS Made Simple (CMSMS) 2.2.11 allows stored XSS by an admin via a crafted image filename on the "file manager > upload images" screen. | ||
| CVE-2018-10032 | Med | 0.31 | 4.8 | 0.01 | Apr 11, 2018 | CMS Made Simple (aka CMSMS) 2.2.7 has Reflected XSS in admin/moduleinterface.php via the m1_version parameter. | ||
| CVE-2018-7893 | Med | 0.31 | 4.8 | 0.01 | Mar 12, 2018 | CMS Made Simple (CMSMS) 2.2.6 has stored XSS in admin/moduleinterface.php via the metadata parameter. | ||
| CVE-2018-5964 | Med | 0.31 | 4.8 | 0.01 | Jan 25, 2018 | CMS Made Simple (CMSMS) 2.2.5 has XSS in admin/moduleinterface.php via the m1_messages parameter. |
- risk 0.64cvss 9.8epss 0.01
CMS Made Simple (CMSMS) before 2.2.5 does not properly cache login information in cookies.
- risk 0.57cvss 8.8epss 0.01
CMS Made Simple (CMSMS) 2.2.7 contains a privilege escalation vulnerability from ordinary user to admin user by arranging for the eff_uid value within $_COOKIE[$this->_loginkey] to equal 1, because files in the tmp/ directory are accessible through HTTP requests. NOTE: this…
- risk 0.49cvss 6.5epss 0.46
class.showtime2_image.php in CMS Made Simple (CMSMS) before 2.2.10 does not ensure that a watermark file has a standard image file extension (GIF, JPG, JPEG, or PNG).
- risk 0.38cvss 5.4epss 0.02
CMS Made Simple (CMSMS) 2.2.15 allows authenticated XSS via the /admin/addbookmark.php script through the Site Admin > My Preferences > Title field.
- risk 0.35cvss 5.3epss 0.01
CMS Made Simple (CMSMS) through 2.2.7 allows physical path leakage via an invalid /index.php?page= value, a crafted URI starting with /index.php?mact=Search, or a direct request to /admin/header.php, /admin/footer.php, /lib/tasks/class.ClearCache.task.php, or…
- risk 0.31cvss 4.8epss 0.01
CMS Made Simple (CMSMS) 2.2.11 allows stored XSS by an admin via a crafted image filename on the "News > Add Article" screen.
- risk 0.31cvss 4.8epss 0.01
CMS Made Simple (CMSMS) 2.2.11 allows stored XSS by an admin via a crafted image filename on the "file manager > upload images" screen.
- risk 0.31cvss 4.8epss 0.01
CMS Made Simple (aka CMSMS) 2.2.7 has Reflected XSS in admin/moduleinterface.php via the m1_version parameter.
- risk 0.31cvss 4.8epss 0.01
CMS Made Simple (CMSMS) 2.2.6 has stored XSS in admin/moduleinterface.php via the metadata parameter.
- risk 0.31cvss 4.8epss 0.01
CMS Made Simple (CMSMS) 2.2.5 has XSS in admin/moduleinterface.php via the m1_messages parameter.