First published: Tue Mar 26 2019(Updated: )
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve unauthenticated blind time-based SQL injection via the m1_idlist parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cmsmadesimple Cms Made Simple | =2.2.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2019-9053 is high with a CVSS score of 8.1.
An attacker can exploit CVE-2019-9053 by sending a crafted URL to the News module, which can lead to unauthenticated blind time-based SQL injection.
CMS Made Simple version 2.2.8 is affected by CVE-2019-9053.
No, authentication is not required to exploit CVE-2019-9053.
To fix CVE-2019-9053, update CMS Made Simple to version 2.2.10 or higher.