CVE-2019-9061

HIGH

CMS Made Simple < 2.2.8 - Authenticated Object Injection via Module Installation

Title source: llm
STIX 2.1

Description

An issue was discovered in CMS Made Simple 2.2.8. In the module ModuleManager (in the file action.installmodule.php), it is possible to reach an unserialize call with untrusted input and achieve authenticated object injection by using the "install module" feature.

References (2)

Core 2
Core References
Release Notes, Vendor Advisory x_refsource_misc
https://newsletter.cmsmadesimple.org/w/89247Qog4jCRCuRinvhsofwg

Scores

CVSS v3 8.8
EPSS 0.0091
EPSS Percentile 76.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-502 CWE-1321
Status published
Products (1)
cmsmadesimple/cms_made_simple < 2.2.8
Published Mar 26, 2019
Tracked Since Feb 18, 2026