Known Vulnerabilities for products from Sdcms
Listed below are 5 of the newest known vulnerabilities associated with the vendor "Sdcms".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2019-9652 json | There is a CSRF in SDCMS V1.7 via an m=admin&c=theme&a=edit request. It allows PHP code injection by providing a filename in ... | 8.8 - HIGH | 2019-03-11 | 2019-03-11 |
| CVE-2019-9651 json | An issue was discovered in SDCMS V1.7. In the \app\admin\controller\themecontroller.php file, the check_bad() function's filt... | 9.8 - CRITICAL | 2019-03-11 | 2019-03-11 |
| CVE-2018-19748 json | app/plug/attachment/controller/admincontroller.php in SDCMS 1.6 allows reading arbitrary files via a /?m=plug&c=admin&a=index... | 7.5 - HIGH | 2018-11-29 | 2018-12-21 |
| CVE-2018-19520 json | An issue was discovered in SDCMS 1.6 with PHP 5.x. app/admin/controller/themecontroller.php uses a check_bad function in an a... | 8.8 - HIGH | 2018-11-25 | 2019-02-04 |
| CVE-2018-11004 json | An issue was discovered in SDcms v1.5. Cross-site request forgery (CSRF) vulnerability in /WWW//app/admin/controller/admincon... | 8.8 - HIGH | 2018-05-12 | 2018-06-18 |
Known software with vulnerabilities from Sdcms
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Sdcms | Sdcms | 1.5 |