CVE-2019-9061

HIGH

CMS Made Simple < 2.2.8 - Authenticated Object Injection via Module Installation

Title source: llm
STIX 2.1

Description

An issue was discovered in CMS Made Simple 2.2.8. In the module ModuleManager (in the file action.installmodule.php), it is possible to reach an unserialize call with untrusted input and achieve authenticated object injection by using the "install module" feature.

References (2)

Core 2
Core References
Release Notes, Vendor Advisory x_refsource_misc
https://newsletter.cmsmadesimple.org/w/89247Qog4jCRCuRinvhsofwg

Scores

CVSS v3 8.8
EPSS 0.0157
EPSS Percentile 72.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-1321 CWE-502
Status published
Products (1)
cmsmadesimple/cms_made_simple < 2.2.8
Published Mar 26, 2019
Tracked Since Feb 18, 2026