CVE-2018-10522: Infoleak
Published Apr 27, 2018
·Updated
In CMS Made Simple (CMSMS) through 2.2.7, the "file view" operation in the admin dashboard contains a sensitive information disclosure vulnerability, exploitable by ordinary users, because the product exposes unrestricted access to the PHP filegetcontents function.
Affected Software
1 affected component
CMSmadesimple CMS Made Simple<=2.2.7
Event History
Apr 27, 2018
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-10522?
CVE-2018-10522 is classified as a medium severity vulnerability affecting CMS Made Simple.
2
How do I fix CVE-2018-10522?
To mitigate CVE-2018-10522, it is recommended to upgrade to CMS Made Simple version 2.2.8 or later.
3
Who is affected by CVE-2018-10522?
CVE-2018-10522 affects all users of CMS Made Simple versions up to and including 2.2.7.
4
What type of vulnerability is CVE-2018-10522?
CVE-2018-10522 is a sensitive information disclosure vulnerability in the admin dashboard.
5
Can ordinary users exploit CVE-2018-10522?
Yes, ordinary users can exploit CVE-2018-10522 due to unrestricted access to sensitive functions.