Vulnerabilities (CVE)

Filtered by vendor Useful Simple Open-source Cms Project Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-21644 1 Useful Simple Open-source Cms Project 1 Useful Simple Open-source Cms 2022-01-21 6.5 MEDIUM 7.2 HIGH
USOC is an open source CMS with a focus on simplicity. In affected versions USOC allows for SQL injection via usersearch.php. In search terms provided by the user were not sanitized and were used directly to construct a sql statement. The only users permitted to search are site admins. Users are advised to upgrade as soon as possible. There are not workarounds for this issue.
CVE-2022-21666 1 Useful Simple Open-source Cms Project 1 Useful Simple Open-source Cms 2022-01-19 6.5 MEDIUM 7.2 HIGH
Useful Simple Open-Source CMS (USOC) is a content management system (CMS) for programmers. Versions prior to Pb2.4Bfx3 allowed Sql injection in usersearch.php only for users with administrative privileges. Users should replace the file `admin/pages/useredit.php` with a newer version. USOC version Pb2.4Bfx3 contains a fixed version of `admin/pages/useredit.php`.