Total
4 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2023-5029 | 1 Chshcms | 1 Mccms | 2024-05-17 | 5.2 MEDIUM | 8.8 HIGH |
A vulnerability, which was classified as critical, was found in mccms 2.6. This affects an unknown part of the file /category/order/hits/copyright/46/finish/1/list/1. The manipulation with the input '"1 leads to sql injection. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-239871. | |||||
CVE-2023-26782 | 1 Chshcms | 1 Mccms | 2024-02-04 | N/A | 6.5 MEDIUM |
An issue discovered in mccms 2.6.1 allows remote attackers to cause a denial of service via Backend management interface ->System Configuration->Cache Configuration->Cache security characters. | |||||
CVE-2023-26781 | 1 Chshcms | 1 Mccms | 2024-02-04 | N/A | 9.8 CRITICAL |
SQL injection vulnerability in mccms 2.6 allows remote attackers to run arbitrary SQL commands via Author Center ->Reader Comments ->Search. | |||||
CVE-2023-29815 | 1 Chshcms | 1 Mccms | 2024-02-04 | N/A | 8.8 HIGH |
mccms v2.6.3 is vulnerable to Cross Site Request Forgery (CSRF). |