Lucene search

K

S@M Cms Security Vulnerabilities

cve
cve

CVE-2024-3800

Sites managed in S@M CMS (Concept Intermedia) might be vulnerable to Reflected XSS via including scripts in requested file names. Only a part of observed services is vulnerable, but since vendor has not investigated the root problem, it is hard to determine when the issue appears.

6.1CVSS

6.5AI Score

0.0005EPSS

2024-06-28 01:15 PM
26
cve
cve

CVE-2024-3801

Sites managed in S@M CMS (Concept Intermedia) might be vulnerable to Reflected XSS via including scripts in one of GET header parameters. Only a part of observed services is vulnerable, but since vendor has not investigated the root problem, it is hard to determine when the issue appears.

6.1CVSS

6.5AI Score

0.0005EPSS

2024-06-28 01:15 PM
26
cve
cve

CVE-2024-3816

Sites managed in S@M CMS (Concept Intermedia) might be vulnerable to a blind SQL Injection executed using the search bar. Only a part of observed services is vulnerable, but since vendor has not investigated the root problem, it is hard to determine when the issue appears.

9.8CVSS

7.7AI Score

0.001EPSS

2024-06-28 01:15 PM
26