First published: Thu Apr 11 2019(Updated: )
An issue was discovered in CMS Made Simple 2.2.8. In the module FrontEndUsers (in the file class.FrontEndUsersManipulate.php or class.FrontEndUsersManipulator.php), it is possible to reach an unserialize call with an untrusted __FEU__ cookie, and achieve authenticated object injection.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cmsmadesimple Cms Made Simple | =2.2.8 | |
=2.2.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2019-9056 is high with a severity value of 8.8.
The affected software of CVE-2019-9056 is CMS Made Simple 2.2.8.
CVE-2019-9056 is a vulnerability in CMS Made Simple 2.2.8 that allows authenticated object injection through an unserialize call with an untrusted __FEU__ cookie.
To fix CVE-2019-9056, it is recommended to upgrade CMS Made Simple to version 2.2.10 or later, as mentioned in the references.
The Common Weakness Enumeration (CWE) of CVE-2019-9056 is 502.