AvaterXXX/CScms

AvaterXXX/CScms

GitHubGitHub
Unavailable
This project is no longer available (or publicly accessible) from GitHub
Releases0

CVE History

CVEPublishedCVSS v3CVSS v2
6.4 MEDIUM

CScms 4.1 allows arbitrary directory deletion via a dir=..\\ substring to plugins\sys\admin\Plugins.php.

7.5 HIGH

CScms 4.1 allows remote code execution, as demonstrated by 1');eval($_POST[cmd]);# in Web Name to upload\plugins\sys\Install.php.

4.3 MEDIUM

\upload\plugins\sys\Install.php in CScms 4.1 has XSS via the site name.

7.5 HIGH

CScms 4.1 allows arbitrary file upload by (for example) adding the php extension to the default filetype list (gif, jpg, png), and then providing a .php pathname within fileurl JSON data.

6.8 MEDIUM

\upload\plugins\sys\admin\Setting.php in CScms 4.1 allows CSRF via admin.php/setting/ftp_save.