CVE-2019-9053: SQL Injection
Published Mar 26, 2019
·Updated
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve unauthenticated blind time-based SQL injection via the m1idlist parameter.
Affected Software
1 affected component
CMSmadesimple CMS Made Simple=2.2.8
Event History
Mar 26, 2019
CVE Published
via MITRE·04:15 PM
Data Sourced
via MITRE·04:15 PM
Description
Data Sourced
via NVD·05:29 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2019-9053?
The severity of CVE-2019-9053 is high with a CVSS score of 8.1.
2
How can an attacker exploit CVE-2019-9053?
An attacker can exploit CVE-2019-9053 by sending a crafted URL to the News module, which can lead to unauthenticated blind time-based SQL injection.
3
What software versions are affected by CVE-2019-9053?
CMS Made Simple version 2.2.8 is affected by CVE-2019-9053.
4
Is authentication required to exploit CVE-2019-9053?
No, authentication is not required to exploit CVE-2019-9053.
5
How can I fix CVE-2019-9053?
To fix CVE-2019-9053, update CMS Made Simple to version 2.2.10 or higher.