Aggregates CVE and security vulnerability intelligence across all idccms_project-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.
Historical issues mainly involve vendor risk csrf and related security problems, affecting vendor surface software deployment and vendor surface production workloads scenarios.
| CVE | Summary | Source | Max CVSS | EPSS % | Published | Updated |
|---|---|---|---|---|---|---|
| CVE-2024-40039 | idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/userGroup_deal.php?mudi=del | [email protected] | 8.8 | 0.32% | 2024-07-09 | 2025-03-13 |
| CVE-2024-40037 | idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/userScore_deal.php?mudi=del | [email protected] | 8.8 | 0.32% | 2024-07-09 | 2024-11-21 |
| CVE-2024-40034 | idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/userLevel_deal.php?mudi=del | [email protected] | 8.8 | 0.28% | 2024-07-09 | 2024-11-21 |
| CVE-2024-36669 | idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component admin/type_deal.php?mudi=add. | [email protected] | 8.8 | 0.23% | 2024-06-05 | 2024-11-21 |
| CVE-2024-36668 | idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component admin/type_deal.php?mudi=del | [email protected] | 8.8 | 0.23% | 2024-06-05 | 2024-11-21 |
| CVE-2024-36667 | idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/idcProType_deal.php?mudi=add&nohrefStr=close | [email protected] | 8.8 | 0.24% | 2024-06-05 | 2024-11-21 |