CVE-2019-9060: Path Traversal
An issue was discovered in CMS Made Simple 2.2.8. It is possible to achieve unauthenticated path traversal in the CGExtensions module (in the file action.setdefaulttemplate.php) with the m1filename parameter; and through the action.showmessage.php file, it is possible to read arbitrary file content (by using that path traversal with m1prefname set to cgerrormsg and m1resettodefault=1).
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-9060?
CVE-2019-9060 is a vulnerability in CMS Made Simple 2.2.8 that allows unauthenticated path traversal and arbitrary file content reading.
How severe is CVE-2019-9060?
CVE-2019-9060 has a severity rating of 7.5 (high).
How does CVE-2019-9060 affect CMS Made Simple?
CVE-2019-9060 affects CMS Made Simple version 2.2.8.
How can I fix CVE-2019-9060?
To fix CVE-2019-9060, upgrade to a version of CMS Made Simple that is not affected by this vulnerability (version 2.2.9 or higher).
Where can I find more information about CVE-2019-9060?
More information about CVE-2019-9060 can be found at the following references: [1] [2] [3].