First published: Fri Sep 17 2021(Updated: )
An issue was discovered in CMS Made Simple 2.2.8. It is possible to achieve unauthenticated path traversal in the CGExtensions module (in the file action.setdefaulttemplate.php) with the m1_filename parameter; and through the action.showmessage.php file, it is possible to read arbitrary file content (by using that path traversal with m1_prefname set to cg_errormsg and m1_resettodefault=1).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cmsmadesimple Cms Made Simple | =2.2.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-9060 is a vulnerability in CMS Made Simple 2.2.8 that allows unauthenticated path traversal and arbitrary file content reading.
CVE-2019-9060 has a severity rating of 7.5 (high).
CVE-2019-9060 affects CMS Made Simple version 2.2.8.
To fix CVE-2019-9060, upgrade to a version of CMS Made Simple that is not affected by this vulnerability (version 2.2.9 or higher).
More information about CVE-2019-9060 can be found at the following references: [1] [2] [3].