CVE-2017-17734: Infoleak
Published Dec 18, 2017
·Updated
CMS Made Simple (CMSMS) before 2.2.5 does not properly cache login information in sessions.
Affected Software
1 affected component
CMSmadesimple CMS Made Simple<2.2.5
Event History
Dec 18, 2017
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-17734?
The severity of CVE-2017-17734 is classified as medium due to the potential for unauthorized access to user accounts.
2
How do I fix CVE-2017-17734?
To fix CVE-2017-17734, upgrade your CMS Made Simple installation to version 2.2.5 or later.
3
What versions of CMS Made Simple are affected by CVE-2017-17734?
CMS Made Simple versions prior to 2.2.5 are affected by CVE-2017-17734.
4
Does CVE-2017-17734 affect the security of user sessions?
Yes, CVE-2017-17734 affects the security of user sessions by improperly caching login information.
5
What type of vulnerability is CVE-2017-17734?
CVE-2017-17734 is a session management vulnerability that can lead to session hijacking.