CVE-2019-9053

HIGH

Cmsmadesimple Cms Made Simple - SQL Injection

Title source: rule

Description

An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve unauthenticated blind time-based SQL injection via the m1_idlist parameter.

Exploits (41)

exploitdb WORKING POC
by Daniele Scanu · pythonwebappsphp
https://www.exploit-db.com/exploits/46635
nomisec WORKING POC 10 stars
by e-renna · poc
https://github.com/e-renna/CVE-2019-9053
nomisec WORKING POC 7 stars
by Mahamedm · poc
https://github.com/Mahamedm/CVE-2019-9053-Exploit-Python-3
nomisec WORKING POC 6 stars
by Dh4nuJ4 · poc
https://github.com/Dh4nuJ4/SimpleCTF-UpdatedExploit
nomisec WORKING POC 5 stars
by ELIZEUOPAIN · poc
https://github.com/ELIZEUOPAIN/CVE-2019-9053-CMS-Made-Simple-2.2.10---SQL-Injection-Exploit
nomisec WORKING POC 3 stars
by h3x0v3rl0rd · poc
https://github.com/h3x0v3rl0rd/CVE-2019-9053
nomisec WORKING POC 1 stars
by JagdeepSinghCeh · poc
https://github.com/JagdeepSinghCeh/cms-made-simple-python3
nomisec WORKING POC 1 stars
by Azrenom · poc
https://github.com/Azrenom/CMS-Made-Simple-2.2.9-CVE-2019-9053
nomisec WORKING POC 1 stars
by TeymurNovruzov · poc
https://github.com/TeymurNovruzov/CVE-2019-9053-python3-remastered
nomisec WORKING POC 1 stars
by fernandobortotti · poc
https://github.com/fernandobortotti/CVE-2019-9053
nomisec WORKING POC 1 stars
by d3athcod3 · poc
https://github.com/d3athcod3/46635.py_CVE-2019-9053
nomisec WORKING POC
by coolkiee · poc
https://github.com/coolkiee/CVE-2019-9053
nomisec WORKING POC
by iTzR1g · poc
https://github.com/iTzR1g/CVE-2019-9053
nomisec WORKING POC
by vadaysakiv · poc
https://github.com/vadaysakiv/cve-2019-9053
nomisec WORKING POC
by pasan2002 · poc
https://github.com/pasan2002/CVE-2019-9053---CMS-Made-Simple-SQL-Injection-Exploit-Modified-
nomisec WORKING POC
by tim-karov · poc
https://github.com/tim-karov/cmsms-sqli
nomisec WRITEUP
by Praditha29 · poc
https://github.com/Praditha29/Simple-CTF-THM-Writeup
nomisec WORKING POC
by Perseus99999 · poc
https://github.com/Perseus99999/CVE-2019-9053-working-
nomisec WORKING POC
by CaelumIsMe · poc
https://github.com/CaelumIsMe/CVE-2019-9053-POC
nomisec WORKING POC
by Slayerma · poc
https://github.com/Slayerma/-CVE-2019-9053
nomisec WORKING POC
by Boon-Rekcah · poc
https://github.com/Boon-Rekcah/CMS-Made-Simple-2.2.9-CVE-2019-9053
nomisec WORKING POC
by louisthedonothing · poc
https://github.com/louisthedonothing/CVE-2019-9053
nomisec WORKING POC
by Kalidas-7 · poc
https://github.com/Kalidas-7/CVE-2019-9053
nomisec WORKING POC
by Hackheart-tech · poc
https://github.com/Hackheart-tech/-exploit-lab
nomisec WORKING POC
by kaizoku73 · poc
https://github.com/kaizoku73/CVE-2019-9053
nomisec WORKING POC
by del0x3 · poc
https://github.com/del0x3/CVE-2019-9053-port-py3
nomisec WORKING POC
by so1icitx · poc
https://github.com/so1icitx/CVE-2019-9053
nomisec WORKING POC
by hf3cyber · poc
https://github.com/hf3cyber/CMS-Made-Simple-2.2.9-Unauthenticated-SQL-Injection-Exploit-CVE-2019-9053-
nomisec WORKING POC
by Yzhacker · poc
https://github.com/Yzhacker/CVE-2019-9053-CMS46635-python3
nomisec WRITEUP
by jtoalu · poc
https://github.com/jtoalu/CTF-CVE-2019-9053-GTFOBins
nomisec WORKING POC
by 0xftorres · poc
https://github.com/0xftorres/CVE-2019-9053-Fixed
nomisec WORKING POC
by Jason-Siu · poc
https://github.com/Jason-Siu/CVE-2019-9053-Exploit-in-Python-3
github NO CODE
by kaushik-reddy · pythonpoc
https://github.com/kaushik-reddy/CVE-s-Working-Exploits/tree/main/CVE-2019-9053
nomisec WORKING POC
by BjarneVerschorre · poc
https://github.com/BjarneVerschorre/CVE-2019-9053
nomisec WORKING POC
by davcwikla · poc
https://github.com/davcwikla/CVE-2019-9053-exploit
nomisec WORKING POC
by byrek · poc
https://github.com/byrek/CVE-2019-9053
nomisec WORKING POC
by kahluri · poc
https://github.com/kahluri/CVE-2019-9053
nomisec STUB
by bthnrml · poc
https://github.com/bthnrml/guncel-cve-2019-9053.py
nomisec WORKING POC
by im-suman-roy · poc
https://github.com/im-suman-roy/CVE-2019-9053
nomisec WORKING POC
by zmiddle · poc
https://github.com/zmiddle/Simple_CMS_SQLi
nomisec WORKING POC
by maraspiras · poc
https://github.com/maraspiras/46635.py

Scores

CVSS v3 8.1
EPSS 0.9256
EPSS Percentile 99.7%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-89
Status published
Products (1)
cmsmadesimple/cms_made_simple 2.2.8
Published Mar 26, 2019
Tracked Since Feb 18, 2026