CVE-2007-5441: Medium severity CMSmadesimple CMS Made Simple vulnerability
CMS Made Simple 1.1.3.1 does not check the permissions assigned to users in some situations, which allows remote authenticated users to perform some administrative actions, as demonstrated by (1) adding a user via a direct request to admin/adduser.php and (2) reading the admin log via an "admin/adminlog.php?page=1" request.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2007-5441?
CVE-2007-5441 is considered a moderate severity vulnerability due to its potential for unauthorized administrative access.
How do I fix CVE-2007-5441?
To fix CVE-2007-5441, upgrade to a patched version of CMS Made Simple that addresses this permission-checking issue.
Who is affected by CVE-2007-5441?
CVE-2007-5441 affects users of CMS Made Simple version 1.1.3.1 who may have remote authenticated access.
What types of actions can be exploited in CVE-2007-5441?
CVE-2007-5441 allows attackers to perform unauthorized administrative actions such as adding users and reading the admin log.
Is there a risk of data breach with CVE-2007-5441?
Yes, CVE-2007-5441 poses a risk of data breach as it permits remote authenticated users to gain elevated permissions.