CVE-2018-10082: Infoleak
CMS Made Simple (CMSMS) through 2.2.7 allows physical path leakage via an invalid /index.php?page= value, a crafted URI starting with /index.php?mact=Search, or a direct request to /admin/header.php, /admin/footer.php, /lib/tasks/class.ClearCache.task.php, or /lib/tasks/class.CmsSecurityCheck.task.php.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-10082?
CVE-2018-10082 has been classified as a medium severity vulnerability.
How does CVE-2018-10082 affect affected versions of CMS Made Simple?
CVE-2018-10082 allows for physical path leakage through various crafted URI requests.
Which versions of CMS Made Simple are vulnerable to CVE-2018-10082?
CMS Made Simple versions up to and including 2.2.7 are vulnerable to CVE-2018-10082.
How can I mitigate the risks associated with CVE-2018-10082?
Mitigating risks for CVE-2018-10082 involves upgrading to a version of CMS Made Simple that is higher than 2.2.7.
Are there any workarounds for CVE-2018-10082 if an upgrade is not immediately possible?
Temporary workarounds for CVE-2018-10082 include restricting access to affected files and disabling specific functionalities.