HIGH
An issue was discovered in CMS Made Simple 2.2.8
Published Mar 26, 2019
8.8
HIGHCVSS 3.0
EPSS 12.28%
Description
An issue was discovered in CMS Made Simple 2.2.8. In the module DesignManager (in the files action.admin_bulk_css.php and action.admin_bulk_template.php), with an unprivileged user with Designer permission, it is possible reach an unserialize call with a crafted value in the m1_allparms parameter, and achieve object injection.
Affected products
No data.
- ≤ 2.2.8
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (4)
- http://packetstormsecurity.com/files/155322/CMS-Made-Simple-2.2.8-Remote-Code-Execution.html x_refsource_MISC
- https://blog.certimetergroup.com/it/articolo/security/CMS_Made_Simple_deserialization_attack_%28CVE-2019-9055%29 x_refsource_MISC
- https://newsletter.cmsmadesimple.org/w/89247Qog4jCRCuRinvhsofwg x_refsource_MISCRelease NotesVendor Advisory
- https://www.cmsmadesimple.org/2019/03/Announcing-CMS-Made-Simple-v2.2.10-Spuzzum x_refsource_CONFIRMRelease NotesVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| http://packetstormsecurity.com/files/155322/CMS-Made-Simple-2.2.8-Remote-Code-Execution.html | x_refsource_MISC | |
| https://blog.certimetergroup.com/it/articolo/security/CMS_Made_Simple_deserialization_attack_%28CVE-2019-9055%29 | x_refsource_MISC | |
| https://newsletter.cmsmadesimple.org/w/89247Qog4jCRCuRinvhsofwg | x_refsource_MISCRelease NotesVendor Advisory | |
| https://www.cmsmadesimple.org/2019/03/Announcing-CMS-Made-Simple-v2.2.10-Spuzzum | x_refsource_CONFIRMRelease NotesVendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Mar 26, 2019
Updated Aug 4, 2024
Reserved Feb 23, 2019
Link CVE-2019-9055
CISA Vulnrichment
Updated n/a