First published: Tue Mar 26 2019(Updated: )
An issue was discovered in CMS Made Simple 2.2.8. In the module ModuleManager (in the file action.installmodule.php), it is possible to reach an unserialize call with untrusted input and achieve authenticated object injection by using the "install module" feature.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cmsmadesimple Cms Made Simple | <=2.2.8 | |
<=2.2.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this issue is CVE-2019-9061.
CVE-2019-9061 has a severity rating of 8.8 (high).
The affected software by CVE-2019-9061 is CMS Made Simple version 2.2.8.
The CWE ID associated with CVE-2019-9061 is CWE-1321 and CWE-502.
To fix CVE-2019-9061, you can update CMS Made Simple to version 2.2.10 or apply the necessary patches.