← Volver a CVEs
CVE-2019-9055
N/ADescripcion
An issue was discovered in CMS Made Simple 2.2.8. In the module DesignManager (in the files action.admin_bulk_css.php and action.admin_bulk_template.php), with an unprivileged user with Designer permission, it is possible reach an unserialize call with a crafted value in the m1_allparms parameter, and achieve object injection.
Detalles CVE
Puntuacion CVSS v3.1N/A
Publicado3/26/2019
Ultima modificacion11/21/2024
Fuentenvd
Avistamientos honeypot0
Productos afectados
cmsmadesimple:cms_made_simple
Debilidades (CWE)
CWE-502
Referencias
http://packetstormsecurity.com/files/155322/CMS-Made-Simple-2.2.8-Remote-Code-Execution.html(cve@mitre.org)
https://blog.certimetergroup.com/it/articolo/security/CMS_Made_Simple_deserialization_attack_%28CVE-2019-9055%29(cve@mitre.org)
http://packetstormsecurity.com/files/155322/CMS-Made-Simple-2.2.8-Remote-Code-Execution.html(af854a3a-2127-422b-91ae-364da2661108)
https://blog.certimetergroup.com/it/articolo/security/CMS_Made_Simple_deserialization_attack_%28CVE-2019-9055%29(af854a3a-2127-422b-91ae-364da2661108)
https://newsletter.cmsmadesimple.org/w/89247Qog4jCRCuRinvhsofwg(af854a3a-2127-422b-91ae-364da2661108)
https://www.cmsmadesimple.org/2019/03/Announcing-CMS-Made-Simple-v2.2.10-Spuzzum(af854a3a-2127-422b-91ae-364da2661108)
Correlaciones IOC
Sin correlaciones registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.