Vulnerabilities (CVE)

Filtered by vendor Macs Cms Project Subscribe
Total 3 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-45503 1 Macs Cms Project 1 Macs Cms 2025-04-18 N/A N/A
SQL Injection vulnerability in Macrob7 Macs CMS 1.1.4f, allows remote attackers to execute arbitrary code, cause a denial of service (DoS), escalate privileges, and obtain sensitive information via crafted payload to resetPassword, forgotPasswordProcess, saveUser, saveRole, deleteUser, deleteRole, deleteComment, deleteUser, allowComment, saveRole, forgotPasswordProcess, resetPassword, saveUser, addComment, saveRole, and saveUser endpoints.
CVE-2020-23045 1 Macs Cms Project 1 Macs Cms 2021-10-29 6.5 MEDIUM 7.2 HIGH
Macrob7 Macs Framework Content Management System - 1.14f was discovered to contain a SQL injection vulnerability via the 'roleId' parameter of the `editRole` and `deletUser` modules.
CVE-2020-23047 1 Macs Cms Project 1 Macs Cms 2021-10-27 4.3 MEDIUM 6.1 MEDIUM
Macrob7 Macs Framework Content Management System - 1.14f was discovered to contain a cross-site scripting (XSS) vulnerability in the search input field of the search module.