CVE-2019-17583: Idreamsoft Icms

High severity, CVSS 7.5. EPSS: 1.3% chance of exploitation in the next 30 days.

idreamsoft iCMS 7.0.15 allows remote attackers to cause a denial of service (resource consumption) via a query for many comments, as demonstrated by the admincp.php?app=comment&perpage= substring followed by a large positive integer.

Affected products

Published 2019-10-14. Last modified 2026-06-17.