📦 Amss\+\+

by Amss\+\+ Project

🔍 What is Amss\+\+?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-2599

CRITICAL CVSS 9.9 Mar 18, 2024

CVE-2024-2599 is a file upload restriction evasion vulnerability in AMSS++ version 4.31 that allows authenticated users to bypass security controls and upload malicious files. This could lead to remot...

CVE-2024-2598

HIGH CVSS 7.1 Mar 18, 2024

CVE-2024-2598 is a cross-site scripting (XSS) vulnerability in AMSS++ version 4.31 that allows remote attackers to inject malicious scripts via user-controlled input in the /amssplus/modules/book/main...

CVE-2024-2594

HIGH CVSS 7.1 Mar 18, 2024

CVE-2024-2594 is a Cross-Site Scripting (XSS) vulnerability in AMSS++ version 4.31 that allows remote attackers to inject malicious scripts via multiple parameters in the admin interface. This could e...

CVE-2024-2596

HIGH CVSS 7.1 Mar 18, 2024

This is a Cross-Site Scripting (XSS) vulnerability in AMSS++ version 4.31 that allows remote attackers to inject malicious scripts via user-controlled input in the /amssplus/modules/mail/main/select_s...

CVE-2024-2590

HIGH CVSS 8.2 Mar 18, 2024

This SQL injection vulnerability in AMSS++ version 4.31 allows remote attackers to execute arbitrary SQL queries through the 'sd_index' parameter in the /amssplus/modules/mail/main/select_send.php end...

CVE-2024-2592

HIGH CVSS 8.2 Mar 18, 2024

This SQL injection vulnerability in AMSS++ version 4.31 allows remote attackers to execute arbitrary SQL queries through the 'person_id' parameter in pic_show.php. This could lead to complete database...

CVE-2024-2584

HIGH CVSS 8.2 Mar 18, 2024

This SQL injection vulnerability in AMSS++ version 4.31 allows remote attackers to execute arbitrary SQL queries through the 'sd_index' parameter in the /amssplus/modules/book/main/select_send.php end...

CVE-2024-2586

HIGH CVSS 8.2 Mar 18, 2024

CVE-2024-2586 is a SQL injection vulnerability in AMSS++ version 4.31 that allows remote attackers to execute arbitrary SQL queries through the 'username' parameter in /amssplus/index.php. This could ...

CVE-2024-2588

HIGH CVSS 8.2 Mar 18, 2024

CVE-2024-2588 is an SQL injection vulnerability in AMSS++ version 4.31 that allows remote attackers to execute arbitrary SQL queries through the '/amssplus/admin/index.php' endpoint's 'id' parameter. ...