ZeroHour

CVE-2019-9056

CVSS 3.0
8.8 high
EPSS
1%p68
Published
()
Modified
Description

An issue was discovered in CMS Made Simple 2.2.8. In the module FrontEndUsers (in the file class.FrontEndUsersManipulate.php or class.FrontEndUsersManipulator.php), it is possible to reach an unserialize call with an untrusted __FEU__ cookie, and achieve authenticated object injection.

Vendors
cmsmadesimple
Products
cms made simple
Weakness
CWE-502
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.