PT-2019-19340 · Cms Made Simple · Cms Made Simple

Publicado

2019-04-11

·

Atualizado

2020-08-24

·

CVE-2019-9056

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions CMS Made Simple version 2.2.8
Description An issue was discovered in the module FrontEndUsers, specifically in the file class.FrontEndUsersManipulate.php or class.FrontEndUsersManipulator.php, where it is possible to reach an unserialize call with an untrusted FEU cookie, and achieve authenticated object injection.
Recommendations For CMS Made Simple version 2.2.8, consider disabling the FrontEndUsers module until a patch is available to prevent authenticated object injection. Restrict access to the class.FrontEndUsersManipulate.php and class.FrontEndUsersManipulator.php files to minimize the risk of exploitation. Avoid using the FEU cookie in the affected module until the issue is resolved.

Correção

Deserialization of Untrusted Data

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-9056

Produtos afetados

Cms Made Simple