Vulnerabilities > Chshcms > Medium

DATE CVE VULNERABILITY TITLE RISK
2023-04-28 CVE-2023-26782 Code Injection vulnerability in Chshcms Mccms 2.6.1
An issue discovered in mccms 2.6.1 allows remote attackers to cause a denial of service via Backend management interface ->System Configuration->Cache Configuration->Cache security characters.
network
low complexity
chshcms CWE-94
6.5
2022-06-09 CVE-2022-30898 Cross-Site Request Forgery (CSRF) vulnerability in Chshcms Cscms 4.2
A Cross-site request forgery (CSRF) vulnerability in Cscms music portal system v4.2 allows remote attackers to change the administrator's username and password.
network
chshcms CWE-352
4.3
2022-05-26 CVE-2022-29661 SQL Injection vulnerability in Chshcms Cscms Music Portal System 4.2
CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/pic/admin/type/save.
network
low complexity
chshcms CWE-89
6.5
2022-05-26 CVE-2022-29662 SQL Injection vulnerability in Chshcms Cscms Music Portal System 4.2
CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the id parameter at /admin.php/news/admin/news/save.
network
low complexity
chshcms CWE-89
6.5
2022-05-26 CVE-2022-29663 SQL Injection vulnerability in Chshcms Cscms Music Portal System 4.2
CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the id parameter at /admin.php/pic/admin/type/hy.
network
low complexity
chshcms CWE-89
6.5
2022-05-26 CVE-2022-29664 SQL Injection vulnerability in Chshcms Cscms Music Portal System 4.2
CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the id parameter at /admin.php/pic/admin/type/pl_save.
network
low complexity
chshcms CWE-89
6.5
2022-05-26 CVE-2022-29665 SQL Injection vulnerability in Chshcms Cscms Music Portal System 4.2
CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the id parameter at /admin.php/news/admin/topic/save.
network
low complexity
chshcms CWE-89
6.5
2022-05-26 CVE-2022-29666 SQL Injection vulnerability in Chshcms Cscms Music Portal System 4.2
CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the id parameter at /admin.php/pic/admin/lists/zhuan.
network
low complexity
chshcms CWE-89
6.5
2022-05-26 CVE-2022-29667 SQL Injection vulnerability in Chshcms Cscms Music Portal System 4.2
CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via /admin.php/pic/admin/pic/hy.
network
low complexity
chshcms CWE-89
6.5
2022-05-26 CVE-2022-29669 SQL Injection vulnerability in Chshcms Cscms Music Portal System 4.2
CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the id parameter at /admin.php/news/admin/lists/zhuan.
network
low complexity
chshcms CWE-89
6.5