Vulnerabilities
18 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-42322 +1 in the same advisory: …42321 | Insecure Permissions vulnerability in icmsdev iCMS v.7.0.16 allows a remote attacker to obtain sensitive information. Insecure Permissions vulnerability in icmsdev iCMS v.7.0.16 allows a remote attacker to obtain sensitive information. NVD description · AI analysis pending | 9.8 group max | <1% |
| — | ||
| CVE-2019-14976 | iCMS 7.0.15 allows admincp.php?app=apps XSS via the keywords parameter. iCMS 7.0.15 allows admincp.php?app=apps XSS via the keywords parameter. NVD description · AI analysis pending | 6.1 | <1% | PoC |
| — | |
| CVE-2019-6259 | An issue was discovered in idreamsoft iCMS V7.0.13. An issue was discovered in idreamsoft iCMS V7.0.13. There is SQL Injection via the app/article/article.admincp.php _data_id parameter. NVD description · AI analysis pending | 9.8 | 2% | PoC |
| — | |
| CVE-2018-18702 | spider.admincp.php in iCMS v7.0.11 allows SQL injection via admincp.php?app=spider&do=import_rule because the upfile content is base64 decoded, deserialized, an spider.admincp.php in iCMS v7.0.11 allows SQL injection via admincp.php?app=spider&do=import_rule because the upfile content is base64 decoded, deserialized, and used for database insertion. NVD description · AI analysis pending | 9.8 | 1% | PoC |
| — | |
| CVE-2018-16314 | An issue was discovered in admincp.php in idreamsoft iCMS 7.0.11. An issue was discovered in admincp.php in idreamsoft iCMS 7.0.11. When verifying CSRF_TOKEN, if CSRF_TOKEN does not exist, only the Referer header is validated, which can be bypassed via an admincp.php substring in this header. NVD description · AI analysis pending | 8.8 | <1% | PoC |
| — | |
| CVE-2018-15895 | An SSRF vulnerability was discovered in idreamsoft iCMS 7.0.11 because the remote function in app/spider/spider_tools.class.php does not block DNS hostnames ass An SSRF vulnerability was discovered in idreamsoft iCMS 7.0.11 because the remote function in app/spider/spider_tools.class.php does not block DNS hostnames associated with private and reserved IP addresses, as demonstrated by 127.0.0.1 in an A record. NOTE: this vulnerability exists because of an incomplete fix for CVE-2018-14858. NVD description · AI analysis pending | 7.5 | 1% | PoC |
| — | |
| CVE-2018-14858 | An SSRF vulnerability was discovered in idreamsoft iCMS before V7.0.11 because the remote function in app/spider/spider_tools.class.php does not block private a An SSRF vulnerability was discovered in idreamsoft iCMS before V7.0.11 because the remote function in app/spider/spider_tools.class.php does not block private and reserved IP addresses such as 10.0.0.0/8. NOTE: this vulnerability exists because of an incomplete fix for CVE-2018-14514. NVD description · AI analysis pending | 7.5 | 1% | PoC |
| — | |
| CVE-2018-14514 | An SSRF vulnerability was discovered in idreamsoft iCMS V7.0.9 that allows attackers to read sensitive files, access an intranet, or possibly have unspecified o An SSRF vulnerability was discovered in idreamsoft iCMS V7.0.9 that allows attackers to read sensitive files, access an intranet, or possibly have unspecified other impact. NVD description · AI analysis pending | 9.8 | 2% | PoC |
| — | |
| CVE-2018-14415 | An issue was discovered in idreamsoft iCMS before 7.0.10. An issue was discovered in idreamsoft iCMS before 7.0.10. XSS exists via the fourth and fifth input elements on the admincp.php?app=prop&do=add screen. NVD description · AI analysis pending | 6.1 | <1% | PoC |
| — | |
| CVE-2018-12498 | spider.admincp.php in iCMS v7.0.8 has SQL Injection via the id parameter in an app=spider&do=batch request to admincp.php. spider.admincp.php in iCMS v7.0.8 has SQL Injection via the id parameter in an app=spider&do=batch request to admincp.php. NVD description · AI analysis pending | 9.8 | 1% | PoC |
| — | |
| CVE-2018-10250 | iCMS V7.0.8 has XSS via the admincp.php keywords parameter in a weixin_category action, aka a WeChat Classified Management keyword search. iCMS V7.0.8 has XSS via the admincp.php keywords parameter in a weixin_category action, aka a WeChat Classified Management keyword search. NVD description · AI analysis pending | 5.4 | <1% | PoC |
| — | |
| CVE-2018-10222 | An issue was discovered in idreamsoft iCMS V7.0. An issue was discovered in idreamsoft iCMS V7.0. There is a CSRF vulnerability that can add a Column via /admincp.php?app=article_category&do=save&frame=iPHP. NVD description · AI analysis pending | 8.8 | <1% | PoC |
| — | |
| CVE-2018-10117 | An issue was discovered in idreamsoft iCMS V7.0.7. An issue was discovered in idreamsoft iCMS V7.0.7. There is a CSRF vulnerability that can add an admin account via admincp.php?app=members&do=save&frame=iPHP. NVD description · AI analysis pending | 8.8 | <1% | PoC |
| — | |
| CVE-2018-9924 | An issue was discovered in idreamsoft iCMS through 7.0.7. An issue was discovered in idreamsoft iCMS through 7.0.7. SQL injection exists via the pid array parameter in an admincp.php?app=tag&do=save&frame=iPHP request. NVD description · AI analysis pending | 9.8 group max | 1% | PoC |
| — |