« Volver al listado

Chshcms

Chshcms Cscms: vulnerabilidades y CVE

Chshcms Cscms tiene 21 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 6 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE21
Últimos 12 meses0
Críticas6
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2022-30898Media (6.5)0.57%—9 jun 2022
A Cross-site request forgery (CSRF) vulnerability in Cscms music portal system v4.2 allows remote attackers to change the administrator's username and password.
CVE-2022-28552Alta (8.8)0.86%—4 may 2022
Cscms 4.1 is vulnerable to SQL Injection. Log into the background, open the song module, create a new song, delete it to the recycle bin, and SQL injection security problems will occur when emptying the recycle bin.
CVE-2022-27369Alta (7.2)0.87%—15 abr 2022
Cscms Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the component news_News.php_hy.
CVE-2022-27368Alta (7.2)0.85%—15 abr 2022
Cscms Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the component dance_Lists.php_zhuan.
CVE-2022-27367Alta (7.2)0.85%—15 abr 2022
Cscms Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the component dance_Topic.php_del.
CVE-2022-27366Alta (7.2)0.85%—15 abr 2022
Cscms Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the component dance_Dance.php_hy.
CVE-2022-27365Alta (7.2)0.96%—15 abr 2022
Cscms Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the component dance_Dance.php_del.
CVE-2022-27090Media (5.4)0.41%—21 mar 2022
Cscms Music Portal System v4.2 was discovered to contain a redirection vulnerability via the backurl parameter.
CVE-2020-28103Crítica (9.8)1.1%—11 ene 2022
cscms v4.1 allows for SQL injection via the "page_del" function.
CVE-2020-28102Crítica (9.8)1.2%—11 ene 2022
cscms v4.1 allows for SQL injection via the "js_del" function.
CVE-2020-21238Crítica (9.8)0.94%—27 dic 2021
An issue in the user login box of CSCMS v4.0 allows attackers to hijack user accounts via brute force attacks.
CVE-2020-22848Crítica (9.8)2.9%—30 ago 2021
A remote code execution (RCE) vulnerability in the \Playsong.php component of cscms v4.1 allows attackers to execute arbitrary commands.
CVE-2019-9598Media (6.5)0.51%—7 mar 2019
An issue was discovered in Cscms 4.1.0. There is an admin.php/pay CSRF vulnerability that can change the payment account to redirect funds.
CVE-2019-6779Alta (8.1)0.45%—24 ene 2019
Cscms 4.1.8 allows admin.php/links/save CSRF to add, modify, or delete friend links.
CVE-2018-17126Crítica (9.8)3.2%—17 sept 2018
CScms 4.1 allows remote code execution, as demonstrated by 1');eval($_POST[cmd]);# in Web Name to upload\plugins\sys\Install.php.
CVE-2018-17125Alta (7.5)1.4%—17 sept 2018
CScms 4.1 allows arbitrary directory deletion via a dir=..\\ substring to plugins\sys\admin\Plugins.php.
CVE-2018-16732Alta (8.8)0.52%—8 sept 2018
\upload\plugins\sys\admin\Setting.php in CScms 4.1 allows CSRF via admin.php/setting/ftp_save.
CVE-2018-16731Crítica (9.8)1.5%—8 sept 2018
CScms 4.1 allows arbitrary file upload by (for example) adding the php extension to the default filetype list (gif, jpg, png), and then providing a .php pathname within fileurl JSON data.
CVE-2018-16730Media (6.1)0.70%—8 sept 2018
\upload\plugins\sys\Install.php in CScms 4.1 has XSS via the site name.
CVE-2018-16448Alta (8.8)0.49%—4 sept 2018
Cscms 4 allows CSRF for creating a member via upload/admin.php/user/save, authenticating vip members via upload/admin.php/user/init/tid and upload/admin.php/user/init/rzid, and creating a super administrator and web…
CVE-2018-16337Media (6.5)0.45%—2 sept 2018
An issue was discovered in Cscms V4.1.8. There is a CSRF vulnerability that can modify a website's basic configuration via upload/admin.php/setting/save.

Otros productos de Chshcms