📦 Idccms

by Idccms

🔍 What is Idccms?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-40331

HIGH CVSS 8.8 Jul 10, 2024

This CSRF vulnerability in idccms v1.35 allows attackers to trick authenticated administrators into performing unauthorized database backup operations. Attackers can force administrators to execute da...

CVE-2024-40329

HIGH CVSS 8.8 Jul 10, 2024

This CSRF vulnerability in idccms v1.35 allows attackers to trick authenticated administrators into performing unauthorized actions, specifically database backup operations via the /admin/softBak_deal...

CVE-2024-40334

HIGH CVSS 8.8 Jul 10, 2024

CVE-2024-40334 is a Cross-Site Request Forgery (CSRF) vulnerability in idccms v1.35 that allows attackers to trick authenticated administrators into performing unauthorized file deletion operations. T...

CVE-2024-40036

HIGH CVSS 8.8 Jul 9, 2024

This CSRF vulnerability in idccms v1.35 allows attackers to trick authenticated administrators into performing unauthorized actions by visiting malicious web pages. Attackers could create new user gro...

CVE-2024-39022

HIGH CVSS 8.8 Jul 5, 2024

CVE-2024-39022 is a Cross-Site Request Forgery vulnerability in idccms v1.35 that allows attackers to trick authenticated administrators into performing unauthorized actions via the /admin/infoSys_dea...

CVE-2024-39158

HIGH CVSS 8.8 Jun 27, 2024

CVE-2024-39158 is a Cross-Site Request Forgery vulnerability in idccms v1.35 that allows attackers to trick authenticated administrators into performing unauthorized actions via the /admin/userSys_dea...

CVE-2024-39154

HIGH CVSS 8.8 Jun 27, 2024

This CSRF vulnerability in idccms v1.35 allows attackers to trick authenticated administrators into performing unauthorized actions by visiting malicious web pages. Attackers can delete keyword data w...

CVE-2024-36548

HIGH CVSS 8.8 Jun 4, 2024

This CSRF vulnerability in idccms V1.35 allows attackers to trick authenticated administrators into performing unauthorized actions, specifically deleting company records via the admin interface. Any ...

CVE-2024-36550

HIGH CVSS 8.8 Jun 4, 2024

This CSRF vulnerability in idccms V1.35 allows attackers to trick authenticated administrators into performing unauthorized actions via crafted requests to the admin panel. Attackers can add VPS compa...

CVE-2024-35552

HIGH CVSS 8.8 May 22, 2024

This CSRF vulnerability in idccms v1.35 allows attackers to trick authenticated administrators into performing unauthorized actions via crafted requests. Attackers could delete logos or potentially pe...

CVE-2024-35556

HIGH CVSS 8.8 May 22, 2024

This CSRF vulnerability in idccms v1.35 allows attackers to trick authenticated administrators into performing unauthorized actions via crafted requests to the /admin/vpsSys_deal.php endpoint. Attacke...

CVE-2024-35558

HIGH CVSS 8.8 May 22, 2024

This CSRF vulnerability in idccms v1.35 allows attackers to trick authenticated administrators into performing unauthorized actions via malicious requests to the /admin/ca_deal.php endpoint. Attackers...

CVE-2024-35108

HIGH CVSS 8.8 May 15, 2024

This CSRF vulnerability in idccms v1.35 allows attackers to trick authenticated administrators into performing unauthorized actions via crafted requests to /admin/homePro_deal.php. Attackers could del...

CVE-2024-35010

HIGH CVSS 8.8 May 14, 2024

This CSRF vulnerability in idccms v1.35 allows attackers to trick authenticated administrators into performing unauthorized actions, specifically deleting banner advertisements via the /admin/banner_d...

CVE-2024-33830

HIGH CVSS 8.1 May 6, 2024

CVE-2024-33830 is a Cross-Site Request Forgery vulnerability in idccms v1.35 that allows attackers to trick authenticated administrators into performing unauthorized actions via the /admin/readDeal.ph...

CVE-2022-27333

HIGH CVSS 7.5 Mar 21, 2022

CVE-2022-27333 allows attackers to delete the install.lock file in idcCMS v1.10, which resets the CMS configuration and data. This affects all users running the vulnerable version of idcCMS, potential...

CVE-2024-40336

MEDIUM CVSS 6.1 Jul 10, 2024

CVE-2024-40336 is a cross-site scripting (XSS) vulnerability in idccms v1.35's Image Advertising Management module. Attackers can inject malicious scripts that execute in users' browsers when viewing ...

CVE-2024-40328

MEDIUM CVSS 6.3 Jul 10, 2024

This CSRF vulnerability in idccms v1.35 allows attackers to trick authenticated administrators into performing unauthorized actions, specifically deleting member online data. It affects all deployment...

CVE-2024-40038

MEDIUM CVSS 5.3 Jul 9, 2024

This CSRF vulnerability in idccms v1.35 allows attackers to trick authenticated administrators into performing unintended actions via the userScore_deal.php endpoint. Attackers can modify user scores ...

CVE-2024-39020

MEDIUM CVSS 6.3 Jul 5, 2024

This CSRF vulnerability in idccms v1.35 allows attackers to trick authenticated administrators into performing unauthorized actions via crafted requests to the vulnerable endpoint. Attackers can modif...

CVE-2024-39119

MEDIUM CVSS 5.4 Jul 2, 2024

This CSRF vulnerability in idccms v1.35 allows attackers to trick authenticated administrators into performing unauthorized actions via the admin/info_deal.php endpoint. Attackers can modify system in...

CVE-2024-39153

MEDIUM CVSS 4.7 Jun 27, 2024

CVE-2024-39153 is a Cross-Site Request Forgery vulnerability in idccms v1.35 that allows attackers to trick authenticated administrators into performing unauthorized actions via the /admin/info_deal.p...

CVE-2024-35554

MEDIUM CVSS 5.4 May 22, 2024

CVE-2024-35554 is a Cross-Site Request Forgery vulnerability in idccms v1.35 that allows attackers to trick authenticated administrators into performing unauthorized actions via the /admin/infoWeb_dea...

CVE-2024-35560

MEDIUM CVSS 4.3 May 22, 2024

This CSRF vulnerability in idccms v1.35 allows attackers to trick authenticated administrators into performing unauthorized deletion operations via crafted requests to /admin/ca_deal.php. Only adminis...

CVE-2024-35550

MEDIUM CVSS 6.3 May 22, 2024

This CSRF vulnerability in idccms v1.35 allows attackers to trick authenticated administrators into performing unauthorized actions via the /admin/infoWeb_deal.php endpoint. Attackers can modify websi...

CVE-2024-34958

MEDIUM CVSS 6.5 May 16, 2024

This CSRF vulnerability in idccms v1.35 allows attackers to trick authenticated administrators into performing unauthorized actions via the banner management interface. Attackers can add malicious ban...

CVE-2024-35012

MEDIUM CVSS 6.3 May 14, 2024

This CSRF vulnerability in idccms v1.35 allows attackers to trick authenticated administrators into performing unauthorized actions by visiting malicious web pages. Attackers could add information typ...

CVE-2024-33829

MEDIUM CVSS 5.4 May 6, 2024

CVE-2024-33829 is a Cross-Site Request Forgery vulnerability in idccms v1.35 that allows attackers to trick authenticated administrators into performing unauthorized actions via the /admin/readDeal.ph...