First published: Sun Oct 14 2007(Updated: )
CMS Made Simple 1.1.3.1 does not check the permissions assigned to users in some situations, which allows remote authenticated users to perform some administrative actions, as demonstrated by (1) adding a user via a direct request to admin/adduser.php and (2) reading the admin log via an "admin/adminlog.php?page=1" request.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Simple CMS | =1.1.3.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-5441 is considered a moderate severity vulnerability due to its potential for unauthorized administrative access.
To fix CVE-2007-5441, upgrade to a patched version of CMS Made Simple that addresses this permission-checking issue.
CVE-2007-5441 affects users of CMS Made Simple version 1.1.3.1 who may have remote authenticated access.
CVE-2007-5441 allows attackers to perform unauthorized administrative actions such as adding users and reading the admin log.
Yes, CVE-2007-5441 poses a risk of data breach as it permits remote authenticated users to gain elevated permissions.