PT-2025-3469 · Cmsimple · Cmsimple

H4Ckr4V3N

·

Publicado

2024-12-26

·

Atualizado

2025-01-28

·

CVE-2024-57548

CVSS v2.0

9.4

Crítica

VetorAV:N/AC:L/Au:N/C:C/I:C/A:N
Name of the Vulnerable Software and Affected Versions CMSimple version 5.16
Description The issue is related to incorrect restriction of a directory path with limited access. Exploitation may allow a remote attacker to gain unauthorized access to protected information by sending a specially crafted GET request. The vulnerability also allows a user to edit the log.php file via the print page.
Recommendations For CMSimple version 5.16, consider restricting access to the print page to prevent unauthorized editing of the log.php file until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Incorrect Default Permissions

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2025-01238
CVE-2024-57548

Produtos afetados

Cmsimple