Known Vulnerabilities for products from Icmsdev
Listed below are 18 of the newest known vulnerabilities associated with the vendor "Icmsdev".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2023-42322 json | Insecure Permissions vulnerability in icmsdev iCMS v.7.0.16 allows a remote attacker to obtain sensitive information. | 9.8 - CRITICAL | 2023-09-20 | 2023-09-23 |
| CVE-2023-42321 json | Cross Site Request Forgery (CSRF) vulnerability in icmsdev iCMSv.7.0.16 allows a remote attacker to execute arbitrary code vi... | 8.8 - HIGH | 2023-09-20 | 2023-09-22 |
| CVE-2019-14976 json | iCMS 7.0.15 allows admincp.php?app=apps XSS via the keywords parameter. | 6.1 - MEDIUM | 2019-08-12 | 2019-08-15 |
| CVE-2019-6259 json | An issue was discovered in idreamsoft iCMS V7.0.13. There is SQL Injection via the app/article/article.admincp.php _data_id p... | 9.8 - CRITICAL | 2019-01-14 | 2019-01-16 |
| CVE-2018-18702 json | spider.admincp.php in iCMS v7.0.11 allows SQL injection via admincp.php?app=spider&do=import_rule because the upfile content ... | 9.8 - CRITICAL | 2018-10-29 | 2018-12-04 |
| CVE-2018-16314 json | An issue was discovered in admincp.php in idreamsoft iCMS 7.0.11. When verifying CSRF_TOKEN, if CSRF_TOKEN does not exist, on... | 8.8 - HIGH | 2018-09-01 | 2018-11-13 |
| CVE-2018-15895 json | An SSRF vulnerability was discovered in idreamsoft iCMS 7.0.11 because the remote function in app/spider/spider_tools.class.p... | 7.5 - HIGH | 2018-08-27 | 2018-11-07 |
| CVE-2018-14858 json | An SSRF vulnerability was discovered in idreamsoft iCMS before V7.0.11 because the remote function in app/spider/spider_tools... | 7.5 - HIGH | 2018-08-02 | 2018-10-03 |
| CVE-2018-14514 json | An SSRF vulnerability was discovered in idreamsoft iCMS V7.0.9 that allows attackers to read sensitive files, access an intra... | 9.8 - CRITICAL | 2018-07-23 | 2018-09-17 |
| CVE-2018-14415 json | An issue was discovered in idreamsoft iCMS before 7.0.10. XSS exists via the fourth and fifth input elements on the admincp.p... | 6.1 - MEDIUM | 2018-07-20 | 2018-09-17 |
| CVE-2018-12498 json | spider.admincp.php in iCMS v7.0.8 has SQL Injection via the id parameter in an app=spider&do=batch request to admincp.php. | 9.8 - CRITICAL | 2018-06-15 | 2018-07-27 |
| CVE-2018-10250 json | iCMS V7.0.8 has XSS via the admincp.php keywords parameter in a weixin_category action, aka a WeChat Classified Management ke... | 5.4 - MEDIUM | 2018-04-20 | 2018-05-21 |
| CVE-2018-10222 json | An issue was discovered in idreamsoft iCMS V7.0. There is a CSRF vulnerability that can add a Column via /admincp.php?app=art... | 8.8 - HIGH | 2018-04-19 | 2018-05-22 |
| CVE-2018-10117 json | An issue was discovered in idreamsoft iCMS V7.0.7. There is a CSRF vulnerability that can add an admin account via admincp.ph... | 8.8 - HIGH | 2018-04-16 | 2018-05-18 |
| CVE-2018-9925 json | An issue was discovered in idreamsoft iCMS through 7.0.7. XSS exists via the nickname field in an admincp.php?app=user&do=sav... | 5.4 - MEDIUM | 2018-04-10 | 2018-04-17 |
| CVE-2018-9924 json | An issue was discovered in idreamsoft iCMS through 7.0.7. SQL injection exists via the pid array parameter in an admincp.php?... | 9.8 - CRITICAL | 2018-04-10 | 2018-04-17 |
| CVE-2018-9923 json | An issue was discovered in idreamsoft iCMS through 7.0.7. CSRF exists in admincp.php, as demonstrated by adding an article vi... | 8.8 - HIGH | 2018-04-10 | 2018-04-17 |
| CVE-2018-9922 json | An issue was discovered in idreamsoft iCMS through 7.0.7. Physical path leakage exists via an invalid nickname field that rev... | 5.3 - MEDIUM | 2018-04-10 | 2018-04-17 |