First published: Mon May 08 2023(Updated: )
SQL Injection vulnerability in CMS Made Simple through 2.2.15 allows remote attackers to execute arbitrary commands via the m1_sortby parameter to modules/News/function.admin_articlestab.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cmsmadesimple Cms Made Simple | <=2.2.15 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-28999 is a SQL Injection vulnerability in CMS Made Simple through version 2.2.15.
CVE-2021-28999 has a severity rating of 8.8 (high).
CVE-2021-28999 allows remote attackers to execute arbitrary commands via the m1_sortby parameter in the modules/News/function.admin_articlestab.php file.
To fix CVE-2021-28999, upgrade CMS Made Simple to version 2.2.16 or higher.
Additional information about CVE-2021-28999 can be found at: [https://seclists.org/fulldisclosure/2021/Mar/49](https://seclists.org/fulldisclosure/2021/Mar/49) and [https://github.com/beerpwn/CVE/blob/master/cms_made_simple_2021/sqli_order_by/CMS-MS-SQLi-report.md](https://github.com/beerpwn/CVE/blob/master/cms_made_simple_2021/sqli_order_by/CMS-MS-SQLi-report.md)