CVE-2019-9056: High severity simple cms vulnerability
An issue was discovered in CMS Made Simple 2.2.8. In the module FrontEndUsers (in the file class.FrontEndUsersManipulate.php or class.FrontEndUsersManipulator.php), it is possible to reach an unserialize call with an untrusted FEU cookie, and achieve authenticated object injection.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-9056?
The severity of CVE-2019-9056 is high with a severity value of 8.8.
What is the affected software of CVE-2019-9056?
The affected software of CVE-2019-9056 is CMS Made Simple 2.2.8.
What is the vulnerability description of CVE-2019-9056?
CVE-2019-9056 is a vulnerability in CMS Made Simple 2.2.8 that allows authenticated object injection through an unserialize call with an untrusted __FEU__ cookie.
How can I fix CVE-2019-9056?
To fix CVE-2019-9056, it is recommended to upgrade CMS Made Simple to version 2.2.10 or later, as mentioned in the references.
What is the Common Weakness Enumeration (CWE) of CVE-2019-9056?
The Common Weakness Enumeration (CWE) of CVE-2019-9056 is 502.