RSS   Vulnerabilities for 'Cscms'   RSS

2022-06-09
 
CVE-2022-30898

CWE-352
 

 
A Cross-site request forgery (CSRF) vulnerability in Cscms music portal system v4.2 allows remote attackers to change the administrator's username and password.

 
2022-05-04
 
CVE-2022-28552

CWE-89
 

 
Cscms 4.1 is vulnerable to SQL Injection. Log into the background, open the song module, create a new song, delete it to the recycle bin, and SQL injection security problems will occur when emptying the recycle bin.

 
2022-04-15
 
CVE-2022-27365

CWE-89
 

 
Cscms Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the component dance_Dance.php_del.

 
 
CVE-2022-27366

CWE-89
 

 
Cscms Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the component dance_Dance.php_hy.

 
 
CVE-2022-27367

CWE-89
 

 
Cscms Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the component dance_Topic.php_del.

 
 
CVE-2022-27368

CWE-89
 

 
Cscms Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the component dance_Lists.php_zhuan.

 
 
CVE-2022-27369

CWE-89
 

 
Cscms Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the component news_News.php_hy.

 
2022-03-21
 
CVE-2022-27090

CWE-601
 

 
Cscms Music Portal System v4.2 was discovered to contain a redirection vulnerability via the backurl parameter.

 
2022-01-11
 
CVE-2020-28102

CWE-89
 

 
cscms v4.1 allows for SQL injection via the "js_del" function.

 
 
CVE-2020-28103

CWE-89
 

 
cscms v4.1 allows for SQL injection via the "page_del" function.

 


Copyright 2024, cxsecurity.com

 

Back to Top