PT-2025-3468 · Cmsimple · Cmsimple
H4Ckr4V3N
·
Published
2024-12-26
·
Updated
2025-01-28
·
CVE-2024-57547
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
CMSimple version 5.16
Description
The issue is related to insecure permissions in the file download functionality of the backup system, allowing a remote attacker to obtain sensitive information. This can be achieved through a crafted script that manipulates the download functionality of php backup files. The vulnerability is associated with incorrect permission assignment for a critical resource, which can enable an attacker to gain unauthorized access to protected information and execute arbitrary code.
Recommendations
For CMSimple version 5.16, consider disabling the backup file download functionality until a patch is available to prevent exploitation. Restrict access to critical resources to minimize the risk of unauthorized information disclosure. Avoid using the vulnerable functionality to download php backup files until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Incorrect Permission
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cmsimple