PT-2025-3467 · Cmsimple · Cmsimple
H4Ckr4V3N
·
Published
2024-12-26
·
Updated
2025-01-28
·
CVE-2024-57546
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
CMSimple version 5.16
Description
The issue in CMSimple is related to insufficient protection of internal data in the link validation function. This can be exploited by a remote attacker to obtain sensitive information via a crafted script. The vulnerability may also allow an attacker to perform a Server-Side Request Forgery (SSRF) attack.
Recommendations
For CMSimple version 5.16, consider disabling the validate link function as a temporary workaround until a patch is available. Restrict access to sensitive information to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Insecure Storage of Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cmsimple