CVE-2019-9057

HIGH

CMS Made Simple < 2.2.8 - Authenticated Object Injection via FilePicker Module

Title source: llm
STIX 2.1

Description

An issue was discovered in CMS Made Simple 2.2.8. In the module FilePicker, it is possible to reach an unserialize call with an untrusted parameter, and achieve authenticated object injection.

References (2)

Core 2
Core References
Release Notes, Vendor Advisory x_refsource_misc
https://newsletter.cmsmadesimple.org/w/89247Qog4jCRCuRinvhsofwg

Scores

CVSS v3 8.8
EPSS 0.0160
EPSS Percentile 72.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-502 CWE-915
Status published
Products (1)
cmsmadesimple/cms_made_simple < 2.2.8
Published Mar 26, 2019
Tracked Since Feb 18, 2026