CVE-2019-9058: High severity simple cms vulnerability
An issue was discovered in CMS Made Simple 2.2.8. In the administrator page admin/changegroupperm.php, it is possible to send a crafted value in the selgroups parameter that leads to authenticated object injection.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-9058?
CVE-2019-9058 has been rated as a high severity vulnerability due to the risk of authenticated object injection.
How do I fix CVE-2019-9058?
To fix CVE-2019-9058, upgrade to CMS Made Simple version 2.2.10 or later.
What makes CVE-2019-9058 a significant vulnerability?
CVE-2019-9058 is significant because it allows authenticated users to perform object injection, potentially compromising the application.
Who is affected by CVE-2019-9058?
CVE-2019-9058 affects all users of CMS Made Simple version 2.2.8 and earlier.
How can I check if my CMS Made Simple installation is vulnerable to CVE-2019-9058?
You can check if your installation is vulnerable by verifying the version number of CMS Made Simple and comparing it to the affected versions.