CVE-2019-9056

HIGH

CMS Made Simple 2.2.8 - Authenticated Object Injection via FrontEndUsers Module

Title source: llm
STIX 2.1

Description

An issue was discovered in CMS Made Simple 2.2.8. In the module FrontEndUsers (in the file class.FrontEndUsersManipulate.php or class.FrontEndUsersManipulator.php), it is possible to reach an unserialize call with an untrusted __FEU__ cookie, and achieve authenticated object injection.

References (2)

Core 2
Core References

Scores

CVSS v3 8.8
EPSS 0.0091
EPSS Percentile 76.0%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-502
Status published
Products (1)
cmsmadesimple/cms_made_simple 2.2.8
Published Apr 11, 2019
Tracked Since Feb 18, 2026