First published: Tue Mar 26 2019(Updated: )
An issue was discovered in CMS Made Simple 2.2.8. In the administrator page admin/changegroupperm.php, it is possible to send a crafted value in the sel_groups parameter that leads to authenticated object injection.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Simple CMS | <=2.2.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-9058 has been rated as a high severity vulnerability due to the risk of authenticated object injection.
To fix CVE-2019-9058, upgrade to CMS Made Simple version 2.2.10 or later.
CVE-2019-9058 is significant because it allows authenticated users to perform object injection, potentially compromising the application.
CVE-2019-9058 affects all users of CMS Made Simple version 2.2.8 and earlier.
You can check if your installation is vulnerable by verifying the version number of CMS Made Simple and comparing it to the affected versions.