PT-2019-19344 · Cms Made Simple · Cms Made Simple
Published
2019-03-26
·
Updated
2022-12-02
·
CVE-2019-9061
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
CMS Made Simple version 2.2.8
Description
An issue was discovered in the ModuleManager module, specifically in the action.installmodule.php file, where it is possible to reach an unserialize call with untrusted input. This can lead to authenticated object injection by using the "install module" feature.
Recommendations
For CMS Made Simple version 2.2.8, consider disabling the "install module" feature in the ModuleManager module until a patch is available to prevent authenticated object injection.
Fix
Deserialization of Untrusted Data
Prototype Pollution
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cms Made Simple