Vulnerabilities (CVE)

Filtered by vendor Chshcms Subscribe
Total 46 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-5029 1 Chshcms 1 Mccms 2024-05-17 5.2 MEDIUM 8.8 HIGH
A vulnerability, which was classified as critical, was found in mccms 2.6. This affects an unknown part of the file /category/order/hits/copyright/46/finish/1/list/1. The manipulation with the input '"1 leads to sql injection. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-239871.
CVE-2023-26782 1 Chshcms 1 Mccms 2024-02-04 N/A 6.5 MEDIUM
An issue discovered in mccms 2.6.1 allows remote attackers to cause a denial of service via Backend management interface ->System Configuration->Cache Configuration->Cache security characters.
CVE-2023-26781 1 Chshcms 1 Mccms 2024-02-04 N/A 9.8 CRITICAL
SQL injection vulnerability in mccms 2.6 allows remote attackers to run arbitrary SQL commands via Author Center ->Reader Comments ->Search.
CVE-2023-29815 1 Chshcms 1 Mccms 2024-02-04 N/A 8.8 HIGH
mccms v2.6.3 is vulnerable to Cross Site Request Forgery (CSRF).
CVE-2022-29682 1 Chshcms 1 Cscms Music Portal System 2024-02-04 6.5 MEDIUM 7.2 HIGH
CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/vod/admin/topic/del.
CVE-2022-29676 1 Chshcms 1 Cscms Music Portal System 2024-02-04 6.5 MEDIUM 7.2 HIGH
CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the id parameter at /admin.php/pic/admin/lists/zhuan.
CVE-2022-29688 1 Chshcms 1 Cscms Music Portal System 2024-02-04 6.5 MEDIUM 7.2 HIGH
CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/singer/admin/singer/hy.
CVE-2022-29664 1 Chshcms 1 Cscms Music Portal System 2024-02-04 6.5 MEDIUM 8.8 HIGH
CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the id parameter at /admin.php/pic/admin/type/pl_save.
CVE-2022-29669 1 Chshcms 1 Cscms Music Portal System 2024-02-04 6.5 MEDIUM 8.8 HIGH
CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the id parameter at /admin.php/news/admin/lists/zhuan.
CVE-2022-29685 1 Chshcms 1 Cscms Music Portal System 2024-02-04 6.5 MEDIUM 8.8 HIGH
CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/User/level_sort.
CVE-2022-29665 1 Chshcms 1 Cscms Music Portal System 2024-02-04 6.5 MEDIUM 7.2 HIGH
CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the id parameter at /admin.php/news/admin/topic/save.
CVE-2022-29660 1 Chshcms 1 Cscms Music Portal System 2024-02-04 7.5 HIGH 9.8 CRITICAL
CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the id parameter at /admin.php/pic/admin/pic/del.
CVE-2022-27090 1 Chshcms 1 Cscms 2024-02-04 4.9 MEDIUM 5.4 MEDIUM
Cscms Music Portal System v4.2 was discovered to contain a redirection vulnerability via the backurl parameter.
CVE-2022-30898 1 Chshcms 1 Cscms 2024-02-04 4.3 MEDIUM 6.5 MEDIUM
A Cross-site request forgery (CSRF) vulnerability in Cscms music portal system v4.2 allows remote attackers to change the administrator's username and password.
CVE-2022-29686 1 Chshcms 1 Cscms Music Portal System 2024-02-04 6.5 MEDIUM 7.2 HIGH
CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/singer/admin/lists/zhuan.
CVE-2022-27365 1 Chshcms 1 Cscms 2024-02-04 6.5 MEDIUM 7.2 HIGH
Cscms Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the component dance_Dance.php_del.
CVE-2022-27368 1 Chshcms 1 Cscms 2024-02-04 6.5 MEDIUM 7.2 HIGH
Cscms Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the component dance_Lists.php_zhuan.
CVE-2022-29663 1 Chshcms 1 Cscms Music Portal System 2024-02-04 6.5 MEDIUM 7.2 HIGH
CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the id parameter at /admin.php/pic/admin/type/hy.
CVE-2022-29667 1 Chshcms 1 Cscms Music Portal System 2024-02-04 6.5 MEDIUM 8.8 HIGH
CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via /admin.php/pic/admin/pic/hy. This vulnerability is exploited via restoring deleted photos.
CVE-2022-28552 1 Chshcms 1 Cscms 2024-02-04 6.5 MEDIUM 8.8 HIGH
Cscms 4.1 is vulnerable to SQL Injection. Log into the background, open the song module, create a new song, delete it to the recycle bin, and SQL injection security problems will occur when emptying the recycle bin.