Chshcms Cscms vulnerabilities
21 known vulnerabilities affecting chshcms/cscms.
Total CVEs
21
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL6HIGH10MEDIUM5
Vulnerabilities
Page 1 of 2
CVE-2020-22848P2CRITICALCVSS 9.8v4.12021-08-30
CVE-2020-22848 [CRITICAL] CVE-2020-22848: A remote code execution (RCE) vulnerability in the \Playsong.php component of cscms v4.1 allows atta
A remote code execution (RCE) vulnerability in the \Playsong.php component of cscms v4.1 allows attackers to execute arbitrary commands.
nvd
CVE-2018-17126P3CRITICALCVSS 9.8v4.12018-09-17
CVE-2018-17126 [CRITICAL] CWE-94 CVE-2018-17126: CScms 4.1 allows remote code execution, as demonstrated by 1');eval($_POST[cmd]);# in Web Name to up
CScms 4.1 allows remote code execution, as demonstrated by 1');eval($_POST[cmd]);# in Web Name to upload\plugins\sys\Install.php.
nvd
CVE-2018-16731P3CRITICALCVSS 9.8v4.12018-09-08
CVE-2018-16731 [CRITICAL] CWE-434 CVE-2018-16731: CScms 4.1 allows arbitrary file upload by (for example) adding the php extension to the default file
CScms 4.1 allows arbitrary file upload by (for example) adding the php extension to the default filetype list (gif, jpg, png), and then providing a .php pathname within fileurl JSON data.
nvd
CVE-2020-28102P3CRITICALCVSS 9.8v4.12022-01-11
CVE-2020-28102 [CRITICAL] CWE-89 CVE-2020-28102: cscms v4.1 allows for SQL injection via the "js_del" function.
cscms v4.1 allows for SQL injection via the "js_del" function.
nvd
CVE-2020-28103P3CRITICALCVSS 9.8v4.12022-01-11
CVE-2020-28103 [CRITICAL] CWE-89 CVE-2020-28103: cscms v4.1 allows for SQL injection via the "page_del" function.
cscms v4.1 allows for SQL injection via the "page_del" function.
nvd
CVE-2022-28552P3HIGHCVSS 8.8v4.12022-05-04
CVE-2022-28552 [HIGH] CWE-89 CVE-2022-28552: Cscms 4.1 is vulnerable to SQL Injection. Log into the background, open the song module, create a ne
Cscms 4.1 is vulnerable to SQL Injection. Log into the background, open the song module, create a new song, delete it to the recycle bin, and SQL injection security problems will occur when emptying the recycle bin.
nvd
CVE-2020-21238P3CRITICALCVSS 9.8v4.02021-12-27
CVE-2020-21238 [CRITICAL] CWE-307 CVE-2020-21238: An issue in the user login box of CSCMS v4.0 allows attackers to hijack user accounts via brute forc
An issue in the user login box of CSCMS v4.0 allows attackers to hijack user accounts via brute force attacks.
nvd
CVE-2022-27365P3HIGHCVSS 7.2v4.22022-04-15
CVE-2022-27365 [HIGH] CWE-89 CVE-2022-27365: Cscms Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the compo
Cscms Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the component dance_Dance.php_del.
nvd
CVE-2022-27368P3HIGHCVSS 7.2v4.22022-04-15
CVE-2022-27368 [HIGH] CWE-89 CVE-2022-27368: Cscms Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the compo
Cscms Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the component dance_Lists.php_zhuan.
nvd
CVE-2022-27369P3HIGHCVSS 7.2v4.22022-04-15
CVE-2022-27369 [HIGH] CWE-89 CVE-2022-27369: Cscms Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the compo
Cscms Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the component news_News.php_hy.
nvd
CVE-2022-27367P3HIGHCVSS 7.2v4.22022-04-15
CVE-2022-27367 [HIGH] CWE-89 CVE-2022-27367: Cscms Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the compo
Cscms Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the component dance_Topic.php_del.
nvd
CVE-2022-27366P3HIGHCVSS 7.2v4.22022-04-15
CVE-2022-27366 [HIGH] CWE-89 CVE-2022-27366: Cscms Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the
Cscms Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the component dance_Dance.php_hy.
nvd
CVE-2018-16448P3HIGHCVSS 8.8v4.02018-09-04
CVE-2018-16448 [HIGH] CWE-352 CVE-2018-16448: Cscms 4 allows CSRF for creating a member via upload/admin.php/user/save, authenticating vip members
Cscms 4 allows CSRF for creating a member via upload/admin.php/user/save, authenticating vip members via upload/admin.php/user/init/tid and upload/admin.php/user/init/rzid, and creating a super administrator and web editor via upload/admin.php/sys/save.
nvd
CVE-2018-17125P3HIGHCVSS 7.5v4.12018-09-17
CVE-2018-17125 [HIGH] CWE-22 CVE-2018-17125: CScms 4.1 allows arbitrary directory deletion via a dir=..\\ substring to plugins\sys\admin\Plugins.
CScms 4.1 allows arbitrary directory deletion via a dir=..\\ substring to plugins\sys\admin\Plugins.php.
nvd
CVE-2018-16732P3HIGHCVSS 8.8v4.12018-09-08
CVE-2018-16732 [HIGH] CWE-352 CVE-2018-16732: \upload\plugins\sys\admin\Setting.php in CScms 4.1 allows CSRF via admin.php/setting/ftp_save.
\upload\plugins\sys\admin\Setting.php in CScms 4.1 allows CSRF via admin.php/setting/ftp_save.
nvd
CVE-2019-6779P4HIGHCVSS 8.1v4.1.82019-01-24
CVE-2019-6779 [HIGH] CWE-352 CVE-2019-6779: Cscms 4.1.8 allows admin.php/links/save CSRF to add, modify, or delete friend links.
Cscms 4.1.8 allows admin.php/links/save CSRF to add, modify, or delete friend links.
nvd
CVE-2022-30898P4MEDIUMCVSS 6.5v4.22022-06-09
CVE-2022-30898 [MEDIUM] CWE-352 CVE-2022-30898: A Cross-site request forgery (CSRF) vulnerability in Cscms music portal system v4.2 allows remote at
A Cross-site request forgery (CSRF) vulnerability in Cscms music portal system v4.2 allows remote attackers to change the administrator's username and password.
nvd
CVE-2019-9598P4MEDIUMCVSS 6.5v4.12019-03-07
CVE-2019-9598 [MEDIUM] CWE-352 CVE-2019-9598: An issue was discovered in Cscms 4.1.0. There is an admin.php/pay CSRF vulnerability that can change
An issue was discovered in Cscms 4.1.0. There is an admin.php/pay CSRF vulnerability that can change the payment account to redirect funds.
nvd
CVE-2018-16337P4MEDIUMCVSS 6.5v4.1.82018-09-02
CVE-2018-16337 [MEDIUM] CWE-352 CVE-2018-16337: An issue was discovered in Cscms V4.1.8. There is a CSRF vulnerability that can modify a website's b
An issue was discovered in Cscms V4.1.8. There is a CSRF vulnerability that can modify a website's basic configuration via upload/admin.php/setting/save.
nvd
CVE-2022-27090P4MEDIUMCVSS 5.4v4.22022-03-21
CVE-2022-27090 [MEDIUM] CWE-601 CVE-2022-27090: Cscms Music Portal System v4.2 was discovered to contain a redirection vulnerability via the backurl
Cscms Music Portal System v4.2 was discovered to contain a redirection vulnerability via the backurl parameter.
nvd
1 / 2Next →