CVE-2019-9693
HIGHCMS Made Simple < 2.2.10 - Authenticated SQL Injection via show_id and picture_id Parameters
Title source: llmDescription
In CMS Made Simple (CMSMS) before 2.2.10, an authenticated user can achieve SQL Injection in class.showtime2_data.php via the functions _updateshow (parameter show_id), _inputshow (parameter show_id), _Getshowinfo (parameter show_id), _Getpictureinfo (parameter picture_id), _AdjustNameSeq (parameter shownumber), _Updatepicture (parameter picture_id), and _Deletepicture (parameter picture_id).
References (2)
Core 2
Core References
Vendor Advisory x_refsource_misc
https://forum.cmsmadesimple.org/viewtopic.php?f=1&t=80285
Scores
CVSS v3
8.8
EPSS
0.0036
EPSS Percentile
58.1%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-89
Status
published
Products (1)
cmsmadesimple/cms_made_simple
< 2.2.10
Published
Mar 11, 2019
Tracked Since
Feb 18, 2026