Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
idreamsoft icms vulnerabilities and exploits
(subscribe to this query)
7.5
CVSSv3
CVE-2021-44977
In iCMS <=8.0.0, a directory traversal vulnerability allows an malicious user to read arbitrary files.
Idreamsoft Icms
9.8
CVSSv3
CVE-2021-44978
iCMS <= 8.0.0 allows users to add and render a comtom template, which has a SSTI vulnerability which causes remote code execution.
Idreamsoft Icms
5.7
CVSSv3
CVE-2019-8902
An issue exists in idreamsoft iCMS up to and including 7.0.14. A CSRF vulnerability can delete users' articles via the public/api.php?app=user URI.
Idreamsoft Icms
6.5
CVSSv3
CVE-2019-16677
An issue exists in idreamsoft iCMS V7.0. admincp.php?app=members&do=del allows CSRF.
Idreamsoft Icms 7.0.0
6.5
CVSSv3
CVE-2020-24739
A CSRF vulnerability was found in iCMS v7.0.0 in the background deletion administrator account. When missing the CSRF_TOKEN and can still request normally, all administrators except the initial administrator will be deleted.
Idreamsoft Icms 7.0.0
7.5
CVSSv3
CVE-2019-7235
An issue exists in idreamsoft iCMS 7.0.13. admincp.php?app=apps&do=save allows directory traversal via _app=/../ to designate an arbitrary directory because of an apps.admincp.php error. This directory can then be deleted via an admincp.php?app=apps&do=uninstall request.
Idreamsoft Icms 7.0.13
8.8
CVSSv3
CVE-2020-21141
iCMS v7.0.15 exists to contain a Cross-Site Request Forgery (CSRF) via /admincp.php?app=members&do=add.
Idreamsoft Icms 7.0.15
8.8
CVSSv3
CVE-2018-16365
An issue exists in idreamsoft iCMS V7.0.10. admincp.php?app=group&do=save allows CSRF.
Idreamsoft Icms 7.0.10
8.8
CVSSv3
CVE-2018-16366
An issue exists in idreamsoft iCMS V7.0.10. admincp.php?app=user&do=save allows CSRF.
Idreamsoft Icms 7.0.10
9.8
CVSSv3
CVE-2020-19527
iCMS 7.0.14 malicious users to execute arbitrary OS commands via shell metacharacters in the DB_NAME parameter to install/install.php.
Idreamsoft Icms 7.0.14
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-4651
CVE-2024-34255
elevation of privilege
CVE-2024-25529
CVE-2024-4671
NULL pointer dereference
CVE-2024-25527
template injection
CVE-2008-0166
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
4
NEXT »