CVE-2007-5441
CMS Made Simple 1.1.3.1 does not check the permissions assigned to users in some situations, which allows remote authenticated users to perform some administrative actions, as demonstrated by (1) adding a user via a direct request to admin/adduser.php…
Does this matter?
Lower severity and a low EPSS score (1.11%). Track it; it rarely justifies an emergency change on its own.
Description
CMS Made Simple 1.1.3.1 does not check the permissions assigned to users in some situations, which allows remote authenticated users to perform some administrative actions, as demonstrated by (1) adding a user via a direct request to admin/adduser.php and (2) reading the admin log via an "admin/adminlog.php?page=1" request.
- CVSS 2.0
- 6.5 MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
- EPSS
- 1.11% probability · 64th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- cmsmadesimple/cms made simple
- Source
- cve@mitre.org
References
- http://blog.cmsmadesimple.org/2007/10/07/announcing-cms-made-simple-1141/
- http://osvdb.org/45481
- http://securityreason.com/securityalert/3223
- http://www.securityfocus.com/archive/1/481984/100/0/threaded
- http://blog.cmsmadesimple.org/2007/10/07/announcing-cms-made-simple-1141/
- http://osvdb.org/45481
- http://securityreason.com/securityalert/3223
- http://www.securityfocus.com/archive/1/481984/100/0/threaded
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.