PT-2021-9126 · Unknown · Cms Made Simple
Calguy1000
·
Published
2021-09-17
·
Updated
2021-09-28
·
CVE-2019-9060
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
CMS Made Simple version 2.2.8
Description
An issue was discovered in the CGExtensions module, allowing unauthenticated path traversal with the
m1 filename parameter in the file action.setdefaulttemplate.php. Additionally, through the action.showmessage.php file, it is possible to read arbitrary file content by using that path traversal with m1 prefname set to cg errormsg and m1 resettodefault set to 1.Recommendations
For CMS Made Simple version 2.2.8, consider disabling the CGExtensions module until a patch is available. As a temporary workaround, restrict access to the action.setdefaulttemplate.php and action.showmessage.php files to minimize the risk of exploitation. Avoid using the
m1 filename parameter in the affected module and the m1 prefname and m1 resettodefault parameters in the action.showmessage.php file until the issue is resolved.Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cms Made Simple