VendorsCMS Made Simplecms_made_simple2.2.2
Vulnerabilities

CMS Made Simple CMS Made Simple 2.2.2

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2017-16784
In CMS Made Simple 2.2.2, there is Reflected XSS via the cntnt01detailtemplate parameter.
Published 2017-11-10 · Modified
6.1EPSS 0.007
CVE-2017-11404
In CMS Made Simple (CMSMS) 2.2.2, remote authenticated administrators can upload a .php file via a FileManager action to admin/moduleinterface.php.
Published 2017-07-18 · Modified
4.9EPSS 0.008
CVE-2017-11405
In CMS Made Simple (CMSMS) 2.2.2, remote authenticated administrators can upload a .php file via a CMSContentManager action to admin/moduleinterface.php, followed by a FilePicker action to admin/moduleinterface.php in which type=image is changed to type=file.
Published 2017-07-18 · Modified
4.9EPSS 0.008