Vulnerabilities
Vulnerable Software
Idreamsoft:  >> Icms  >> 7.0.10  Security Vulnerabilities
In iCMS <=8.0.0, a directory traversal vulnerability allows an attacker to read arbitrary files.
CVSS Score
7.5
EPSS Score
0.005
Published
2022-02-04
iCMS <= 8.0.0 allows users to add and render a comtom template, which has a SSTI vulnerability which causes remote code execution.
CVSS Score
9.8
EPSS Score
0.027
Published
2022-02-04
An issue was discovered in idreamsoft iCMS through 7.0.14. A CSRF vulnerability can delete users' articles via the public/api.php?app=user URI.
CVSS Score
5.7
EPSS Score
0.001
Published
2019-02-18
An issue was discovered in idreamsoft iCMS V7.0.10. admincp.php?app=user&do=save allows CSRF.
CVSS Score
8.8
EPSS Score
0.001
Published
2018-09-02
An issue was discovered in idreamsoft iCMS V7.0.10. admincp.php?app=group&do=save allows CSRF.
CVSS Score
8.8
EPSS Score
0.001
Published
2018-09-02


Contact Us

Shodan ® - All rights reserved