PT-2021-9126 · Unknown · Cms Made Simple

Calguy1000

·

Published

2021-09-17

·

Updated

2021-09-28

·

CVE-2019-9060

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions CMS Made Simple version 2.2.8
Description An issue was discovered in the CGExtensions module, allowing unauthenticated path traversal with the m1 filename parameter in the file action.setdefaulttemplate.php. Additionally, through the action.showmessage.php file, it is possible to read arbitrary file content by using that path traversal with m1 prefname set to cg errormsg and m1 resettodefault set to 1.
Recommendations For CMS Made Simple version 2.2.8, consider disabling the CGExtensions module until a patch is available. As a temporary workaround, restrict access to the action.setdefaulttemplate.php and action.showmessage.php files to minimize the risk of exploitation. Avoid using the m1 filename parameter in the affected module and the m1 prefname and m1 resettodefault parameters in the action.showmessage.php file until the issue is resolved.

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-9060

Affected Products

Cms Made Simple