Products

  • CMS1 vulnerability

Showing 1 vulnerability on this page

Signals CISA KEV Ransomware Nuclei
Sarman Soft Software and Technology Services Industry and Trade Ltd. Co. vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Authentication Bypass in Sarman Soft's CMS

Execution After Redirect (EAR) vulnerability in Sarman Soft Software and Technology Services Industry and Trade Ltd. Co. CMS allows JSON Hijacking (aka JavaScript Hijacking), Authentication Bypass. This issue affects CMS: through 10022026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CWE-698Feb 10, 2026
CVSS8.7v3.1EPSS0.449%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX