CVE-2021-28999: SQL Injection
SQL Injection vulnerability in CMS Made Simple through 2.2.15 allows remote attackers to execute arbitrary commands via the m1sortby parameter to modules/News/function.adminarticlestab.php.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-28999?
CVE-2021-28999 is a SQL Injection vulnerability in CMS Made Simple through version 2.2.15.
How severe is CVE-2021-28999?
CVE-2021-28999 has a severity rating of 8.8 (high).
How does CVE-2021-28999 impact the affected software?
CVE-2021-28999 allows remote attackers to execute arbitrary commands via the m1_sortby parameter in the modules/News/function.admin_articlestab.php file.
How can I fix CVE-2021-28999?
To fix CVE-2021-28999, upgrade CMS Made Simple to version 2.2.16 or higher.
Where can I find more information about CVE-2021-28999?
Additional information about CVE-2021-28999 can be found at: [https://seclists.org/fulldisclosure/2021/Mar/49](https://seclists.org/fulldisclosure/2021/Mar/49) and [https://github.com/beerpwn/CVE/blob/master/cms_made_simple_2021/sqli_order_by/CMS-MS-SQLi-report.md](https://github.com/beerpwn/CVE/blob/master/cms_made_simple_2021/sqli_order_by/CMS-MS-SQLi-report.md)