CVE-2019-9060

HIGH

CMS Made Simple 2.2.8 - Unauthenticated Path Traversal and Arbitrary File Read via CGExtensions Module

Title source: llm
STIX 2.1

Description

An issue was discovered in CMS Made Simple 2.2.8. It is possible to achieve unauthenticated path traversal in the CGExtensions module (in the file action.setdefaulttemplate.php) with the m1_filename parameter; and through the action.showmessage.php file, it is possible to read arbitrary file content (by using that path traversal with m1_prefname set to cg_errormsg and m1_resettodefault=1).

References (4)

Core 4
Core References
Release Notes, Vendor Advisory x_refsource_confirm
http://dev.cmsmadesimple.org/project/changelog/5819
Vendor Advisory x_refsource_confirm
https://forum.cmsmadesimple.org/viewtopic.php?f=1&t=80285

Scores

CVSS v3 7.5
EPSS 0.0042
EPSS Percentile 61.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-22
Status published
Products (1)
cmsmadesimple/cms_made_simple 2.2.8
Published Sep 17, 2021
Tracked Since Feb 18, 2026