First published: Wed Mar 05 2014(Updated: )
SQL injection vulnerability in the News module in CMS Made Simple (CMSMS) before 1.11.10 allows remote authenticated users with the "Modify News" permission to execute arbitrary SQL commands via the sortby parameter to admin/moduleinterface.php. NOTE: some of these details are obtained from third party information.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Simple CMS | <=1.11.9 | |
Simple CMS | =0.1 | |
Simple CMS | =0.2 | |
Simple CMS | =0.2.1 | |
Simple CMS | =0.3 | |
Simple CMS | =0.3.1 | |
Simple CMS | =0.3.2 | |
Simple CMS | =0.4 | |
Simple CMS | =0.4.1 | |
Simple CMS | =0.5 | |
Simple CMS | =0.5.1 | |
Simple CMS | =0.6 | |
Simple CMS | =0.6.1 | |
Simple CMS | =0.6.2 | |
Simple CMS | =0.6.3 | |
Simple CMS | =0.7 | |
Simple CMS | =0.7.1 | |
Simple CMS | =0.7.2 | |
Simple CMS | =0.7.3 | |
Simple CMS | =0.8 | |
Simple CMS | =0.8.1 | |
Simple CMS | =0.8.2 | |
Simple CMS | =0.9 | |
Simple CMS | =0.9.1 | |
Simple CMS | =0.9.2 | |
Simple CMS | =0.10 | |
Simple CMS | =0.10.1 | |
Simple CMS | =0.10.2 | |
Simple CMS | =0.10.3 | |
Simple CMS | =0.10.4 | |
Simple CMS | =0.11 | |
Simple CMS | =0.11.1 | |
Simple CMS | =0.11.2 | |
Simple CMS | =0.12 | |
Simple CMS | =0.12.1 | |
Simple CMS | =0.12.2 | |
Simple CMS | =0.13 | |
Simple CMS | =1.0 | |
Simple CMS | =1.0.1 | |
Simple CMS | =1.0.2 | |
Simple CMS | =1.0.3 | |
Simple CMS | =1.0.4 | |
Simple CMS | =1.0.5 | |
Simple CMS | =1.0.6 | |
Simple CMS | =1.1 | |
Simple CMS | =1.1.1 | |
Simple CMS | =1.1.2 | |
Simple CMS | =1.1.3 | |
Simple CMS | =1.1.3.1 | |
Simple CMS | =1.1.4 | |
Simple CMS | =1.10 | |
Simple CMS | =1.10.1 | |
Simple CMS | =1.10.2 | |
Simple CMS | =1.10.3 | |
Simple CMS | =1.11 | |
Simple CMS | =1.11.1 | |
Simple CMS | =1.11.2 | |
Simple CMS | =1.11.2.1 | |
Simple CMS | =1.11.3 | |
Simple CMS | =1.11.4 | |
Simple CMS | =1.11.5 | |
Simple CMS | =1.11.6 | |
Simple CMS | =1.11.7 | |
Simple CMS | =1.11.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-2245 has been classified as a high severity SQL injection vulnerability.
To fix CVE-2014-2245, upgrade to CMS Made Simple version 1.11.10 or later.
Only authenticated users with the 'Modify News' permission in CMS Made Simple versions prior to 1.11.10 are affected.
CVE-2014-2245 is an SQL injection vulnerability allowing attackers to execute arbitrary SQL commands.
CVE-2014-2245 was published in March 2014.