Filtered by vendor Chshcms
Subscribe
Total
46 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2023-26782 | 1 Chshcms | 1 Mccms | 2025-01-31 | N/A | 6.5 MEDIUM |
An issue discovered in mccms 2.6.1 allows remote attackers to cause a denial of service via Backend management interface ->System Configuration->Cache Configuration->Cache security characters. | |||||
CVE-2023-26781 | 1 Chshcms | 1 Mccms | 2025-01-31 | N/A | 9.8 CRITICAL |
SQL injection vulnerability in mccms 2.6 allows remote attackers to run arbitrary SQL commands via Author Center ->Reader Comments ->Search. | |||||
CVE-2023-29815 | 1 Chshcms | 1 Mccms | 2025-01-30 | N/A | 8.8 HIGH |
mccms v2.6.3 is vulnerable to Cross Site Request Forgery (CSRF). | |||||
CVE-2023-5029 | 1 Chshcms | 1 Mccms | 2024-11-21 | 5.2 MEDIUM | 5.5 MEDIUM |
A vulnerability, which was classified as critical, was found in mccms 2.6. This affects an unknown part of the file /category/order/hits/copyright/46/finish/1/list/1. The manipulation with the input '"1 leads to sql injection. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-239871. | |||||
CVE-2022-30898 | 1 Chshcms | 1 Cscms | 2024-11-21 | 4.3 MEDIUM | 6.5 MEDIUM |
A Cross-site request forgery (CSRF) vulnerability in Cscms music portal system v4.2 allows remote attackers to change the administrator's username and password. | |||||
CVE-2022-29689 | 1 Chshcms | 1 Cscms Music Portal System | 2024-11-21 | 6.5 MEDIUM | 7.2 HIGH |
CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/singer/admin/singer/del. | |||||
CVE-2022-29688 | 1 Chshcms | 1 Cscms Music Portal System | 2024-11-21 | 6.5 MEDIUM | 7.2 HIGH |
CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/singer/admin/singer/hy. | |||||
CVE-2022-29687 | 1 Chshcms | 1 Cscms Music Portal System | 2024-11-21 | 6.5 MEDIUM | 7.2 HIGH |
CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/user/level_del. | |||||
CVE-2022-29686 | 1 Chshcms | 1 Cscms Music Portal System | 2024-11-21 | 6.5 MEDIUM | 7.2 HIGH |
CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/singer/admin/lists/zhuan. | |||||
CVE-2022-29685 | 1 Chshcms | 1 Cscms Music Portal System | 2024-11-21 | 6.5 MEDIUM | 8.8 HIGH |
CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/User/level_sort. | |||||
CVE-2022-29684 | 1 Chshcms | 1 Cscms Music Portal System | 2024-11-21 | 6.5 MEDIUM | 7.2 HIGH |
CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/Label/js_del. | |||||
CVE-2022-29683 | 1 Chshcms | 1 Cscms Music Portal System | 2024-11-21 | 6.5 MEDIUM | 7.2 HIGH |
CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/Label/page_del. | |||||
CVE-2022-29682 | 1 Chshcms | 1 Cscms Music Portal System | 2024-11-21 | 6.5 MEDIUM | 7.2 HIGH |
CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/vod/admin/topic/del. | |||||
CVE-2022-29681 | 1 Chshcms | 1 Cscms Music Portal System | 2024-11-21 | 6.5 MEDIUM | 7.2 HIGH |
CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/Links/del. | |||||
CVE-2022-29680 | 1 Chshcms | 1 Cscms Music Portal System | 2024-11-21 | 6.5 MEDIUM | 7.2 HIGH |
CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/user/zu_del. | |||||
CVE-2022-29676 | 1 Chshcms | 1 Cscms Music Portal System | 2024-11-21 | 6.5 MEDIUM | 7.2 HIGH |
CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the id parameter at /admin.php/pic/admin/lists/zhuan. | |||||
CVE-2022-29670 | 1 Chshcms | 1 Cscms Music Portal System | 2024-11-21 | 6.5 MEDIUM | 7.2 HIGH |
CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the id parameter at /admin.php/pic/admin/type/del. | |||||
CVE-2022-29669 | 1 Chshcms | 1 Cscms Music Portal System | 2024-11-21 | 6.5 MEDIUM | 8.8 HIGH |
CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the id parameter at /admin.php/news/admin/lists/zhuan. | |||||
CVE-2022-29667 | 1 Chshcms | 1 Cscms Music Portal System | 2024-11-21 | 6.5 MEDIUM | 8.8 HIGH |
CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via /admin.php/pic/admin/pic/hy. This vulnerability is exploited via restoring deleted photos. | |||||
CVE-2022-29666 | 1 Chshcms | 1 Cscms Music Portal System | 2024-11-21 | 6.5 MEDIUM | 7.2 HIGH |
CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the id parameter at /admin.php/pic/admin/lists/zhuan. |