PT-2019-19341 · Cms Made Simple · Cms Made Simple
CVE-2019-9057
·
Publicado
2019-03-26
·
Atualizado
2022-12-02
CVSS v3.1
8.8
Alta
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
CMS Made Simple version 2.2.8
Description
An issue was discovered in the FilePicker module, where it is possible to reach an unserialize call with an untrusted parameter, achieving authenticated object injection.
Recommendations
For CMS Made Simple version 2.2.8, consider restricting access to the FilePicker module to minimize the risk of exploitation until a patch is available.
Correção
Deserialization of Untrusted Data
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Cms Made Simple