CVE-2018-1000158: High severity simple cms vulnerability
cmsmadesimple version 2.2.7 contains a Incorrect Access Control vulnerability in the function of sendrecoveryemail in the line "$url = $config['adminurl'] . '/login.php?recoverme=' . $code;" that can result in Administrator Password Reset Poisoning, specifically a reset URL pointing at an attacker controlled server can be created by using a host header attack.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-1000158?
CVE-2018-1000158 is classified as a moderate severity vulnerability due to its potential to expose sensitive information and impact user security.
How can CVE-2018-1000158 be exploited?
CVE-2018-1000158 can be exploited through an incorrect access control vulnerability that allows an attacker to manipulate password reset URLs.
How do I fix CVE-2018-1000158?
To fix CVE-2018-1000158, it is recommended to upgrade CMS Made Simple to a version that addresses this vulnerability.
What versions of CMS Made Simple are affected by CVE-2018-1000158?
CVE-2018-1000158 specifically affects CMS Made Simple version 2.2.7.
How does CVE-2018-1000158 affect system security?
CVE-2018-1000158 can lead to administrative account compromise by allowing attackers to reset passwords using malformed URLs.