Vulnerabilities (CVE)

Filtered by vendor Cmsmadesimple Subscribe
Filtered by product Cms Made Simple
Total 147 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-10523 1 Cmsmadesimple 1 Cms Made Simple 2023-12-10 5.0 MEDIUM 5.3 MEDIUM
CMS Made Simple (CMSMS) through 2.2.7 contains a physical path leakage Vulnerability via /modules/DesignManager/action.ajax_get_templates.php, /modules/DesignManager/action.ajax_get_stylesheets.php, /modules/FileManager/dunzip.php, or /modules/FileManager/untgz.php.
CVE-2018-10517 1 Cmsmadesimple 1 Cms Made Simple 2023-12-10 6.5 MEDIUM 7.2 HIGH
In CMS Made Simple (CMSMS) through 2.2.7, the "module import" operation in the admin dashboard contains a remote code execution vulnerability, exploitable by an admin user, because an XML Package can contain base64-encoded PHP code in a data element.
CVE-2018-7448 1 Cmsmadesimple 1 Cms Made Simple 2023-12-10 8.5 HIGH 7.5 HIGH
Remote code execution vulnerability in /cmsms-2.1.6-install.php/index.php in CMS Made Simple version 2.1.6 allows remote attackers to inject arbitrary PHP code via the "timezone" parameter in step 4 of a fresh installation procedure.
CVE-2018-1000158 1 Cmsmadesimple 1 Cms Made Simple 2023-12-10 4.3 MEDIUM 8.8 HIGH
cmsmadesimple version 2.2.7 contains a Incorrect Access Control vulnerability in the function of send_recovery_email in the line "$url = $config['admin_url'] . '/login.php?recoverme=' . $code;" that can result in Administrator Password Reset Poisoning, specifically a reset URL pointing at an attacker controlled server can be created by using a host header attack.
CVE-2018-7893 1 Cmsmadesimple 1 Cms Made Simple 2023-12-10 3.5 LOW 4.8 MEDIUM
CMS Made Simple (CMSMS) 2.2.6 has stored XSS in admin/moduleinterface.php via the metadata parameter.
CVE-2018-1000094 1 Cmsmadesimple 1 Cms Made Simple 2023-12-10 6.5 MEDIUM 7.2 HIGH
CMS Made Simple version 2.2.5 contains a Remote Code Execution vulnerability in File Manager that can result in Allows an authenticated admin that has access to the file manager to execute code on the server. This attack appear to be exploitable via File upload -> copy to any extension.
CVE-2018-8058 1 Cmsmadesimple 1 Cms Made Simple 2023-12-10 3.5 LOW 4.8 MEDIUM
CMS Made Simple (CMSMS) 2.2.6 has XSS in admin/moduleinterface.php via the pagedata parameter.
CVE-2018-10521 1 Cmsmadesimple 1 Cms Made Simple 2023-12-10 4.0 MEDIUM 2.7 LOW
In CMS Made Simple (CMSMS) through 2.2.7, the "file move" operation in the admin dashboard contains an arbitrary file movement vulnerability that can cause DoS, exploitable by an admin user, because config.php can be moved into an incorrect directory.
CVE-2018-10084 1 Cmsmadesimple 1 Cms Made Simple 2023-12-10 6.5 MEDIUM 8.8 HIGH
CMS Made Simple (CMSMS) through 2.2.6 contains a privilege escalation vulnerability from ordinary user to admin user by arranging for the eff_uid value within $_COOKIE[$this->_loginkey] to equal 1, because an SHA-1 cryptographic protection mechanism can be bypassed.
CVE-2018-5965 1 Cmsmadesimple 1 Cms Made Simple 2023-12-10 3.5 LOW 4.8 MEDIUM
CMS Made Simple (CMSMS) 2.2.5 has XSS in admin/moduleinterface.php via the m1_errors parameter.
CVE-2018-10032 1 Cmsmadesimple 1 Cms Made Simple 2023-12-10 3.5 LOW 4.8 MEDIUM
CMS Made Simple (aka CMSMS) 2.2.7 has Reflected XSS in admin/moduleinterface.php via the m1_version parameter.
CVE-2018-10520 1 Cmsmadesimple 1 Cms Made Simple 2023-12-10 8.5 HIGH 6.5 MEDIUM
In CMS Made Simple (CMSMS) through 2.2.7, the "module remove" operation in the admin dashboard contains an arbitrary file deletion vulnerability that can cause DoS, exploitable by an admin user, because the attacker can remove all lib/ files in all directories.
CVE-2018-10516 1 Cmsmadesimple 1 Cms Made Simple 2023-12-10 5.5 MEDIUM 6.5 MEDIUM
In CMS Made Simple (CMSMS) through 2.2.7, the "file rename" operation in the admin dashboard contains a sensitive information disclosure vulnerability, exploitable by an admin user, that can cause DoS by moving config.php to the upload/ directory.
CVE-2018-10086 1 Cmsmadesimple 1 Cms Made Simple 2023-12-10 6.5 MEDIUM 7.2 HIGH
CMS Made Simple (CMSMS) through 2.2.7 contains an arbitrary code execution vulnerability in the admin dashboard because the implementation uses "eval('function testfunction'.rand()" and it is possible to bypass certain restrictions on these "testfunction" functions.
CVE-2018-10519 1 Cmsmadesimple 1 Cms Made Simple 2023-12-10 6.5 MEDIUM 8.8 HIGH
CMS Made Simple (CMSMS) 2.2.7 contains a privilege escalation vulnerability from ordinary user to admin user by arranging for the eff_uid value within $_COOKIE[$this->_loginkey] to equal 1, because files in the tmp/ directory are accessible through HTTP requests. NOTE: this vulnerability exists because of an incorrect fix for CVE-2018-10084.
CVE-2018-5963 1 Cmsmadesimple 1 Cms Made Simple 2023-12-10 3.5 LOW 4.8 MEDIUM
CMS Made Simple (CMSMS) 2.2.5 has XSS in admin/addbookmark.php via the title parameter.
CVE-2018-9921 1 Cmsmadesimple 1 Cms Made Simple 2023-12-10 5.0 MEDIUM 5.3 MEDIUM
In CMS Made Simple 2.2.7, a Directory Traversal issue makes it possible to determine the existence of files and directories outside the web-site installation directory, and determine whether a file has contents matching a specified checksum. The attack uses an admin/checksum.php?__c= request.
CVE-2018-1000092 1 Cmsmadesimple 1 Cms Made Simple 2023-12-10 6.8 MEDIUM 8.8 HIGH
CMS Made Simple version versions 2.2.5 contains a Cross ite Request Forgery (CSRF) vulnerability in Admin profile page that can result in Details can be found here http://dev.cmsmadesimple.org/bug/view/11715. This attack appear to be exploitable via A specially crafted web page. This vulnerability appears to have been fixed in 2.2.6.
CVE-2018-10083 1 Cmsmadesimple 1 Cms Made Simple 2023-12-10 6.4 MEDIUM 7.5 HIGH
CMS Made Simple (CMSMS) through 2.2.7 contains an arbitrary file deletion vulnerability in the admin dashboard via directory traversal sequences in the val parameter within a cmd=del request, because code under modules\FilePicker does not restrict the val parameter.
CVE-2018-10033 1 Cmsmadesimple 1 Cms Made Simple 2023-12-10 3.5 LOW 4.8 MEDIUM
CMS Made Simple (aka CMSMS) 2.2.7 has Stored XSS in admin/siteprefs.php via the metadata parameter.