PT-2025-3467 · Cmsimple · Cmsimple

H4Ckr4V3N

·

Published

2024-12-26

·

Updated

2025-01-28

·

CVE-2024-57546

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions CMSimple version 5.16
Description The issue in CMSimple is related to insufficient protection of internal data in the link validation function. This can be exploited by a remote attacker to obtain sensitive information via a crafted script. The vulnerability may also allow an attacker to perform a Server-Side Request Forgery (SSRF) attack.
Recommendations For CMSimple version 5.16, consider disabling the validate link function as a temporary workaround until a patch is available. Restrict access to sensitive information to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Insecure Storage of Sensitive Information

Weakness Enumeration

Related Identifiers

BDU:2025-01236
CVE-2024-57546

Affected Products

Cmsimple