CVE-2018-10085: Critical severity simple cms vulnerability
CMS Made Simple (CMSMS) through 2.2.6 allows PHP object injection because of an unserialize call in the getdata function of \lib\classes\internal\class.LoginOperations.php. By sending a crafted cookie, a remote attacker can upload and execute code, or delete files.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-10085?
CVE-2018-10085 is classified as a high severity vulnerability due to its potential for remote code execution.
How do I fix CVE-2018-10085?
To fix CVE-2018-10085, upgrade to CMS Made Simple version 2.2.7 or later.
What is the impact of CVE-2018-10085?
The impact of CVE-2018-10085 can include unauthorized code execution, file deletion, and overall system compromise.
What versions of CMS Made Simple are affected by CVE-2018-10085?
CVE-2018-10085 affects all CMS Made Simple versions prior to 2.2.7.
How does CVE-2018-10085 allow an attacker to exploit the system?
CVE-2018-10085 allows an attacker to exploit the system via PHP object injection through a crafted cookie sent to the affected application.