CVE-2014-2245
SQL injection vulnerability in the News module in CMS Made Simple (CMSMS) before 1.11.10 allows remote authenticated users with the "Modify News" permission to execute arbitrary SQL commands via the sortby parameter to admin/moduleinterface.php.
Does this matter?
Lower severity and a low EPSS score (0.98%). Track it; it rarely justifies an emergency change on its own.
Description
SQL injection vulnerability in the News module in CMS Made Simple (CMSMS) before 1.11.10 allows remote authenticated users with the "Modify News" permission to execute arbitrary SQL commands via the sortby parameter to admin/moduleinterface.php. NOTE: some of these details are obtained from third party information.
- CVSS 2.0
- 6.0 MEDIUMAV:N/AC:M/Au:S/C:P/I:P/A:P
- EPSS
- 0.98% probability · 60th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-89
- Affected
- cmsmadesimple/cms made simple
- Source
- cve@mitre.org
References
- http://dev.cmsmadesimple.org/project/changelog/4602Vendor Advisory
- http://seclists.org/oss-sec/2014/q1/467
- http://secunia.com/advisories/56996Vendor Advisory
- http://www.securityfocus.com/bid/65953
- http://dev.cmsmadesimple.org/project/changelog/4602Vendor Advisory
- http://seclists.org/oss-sec/2014/q1/467
- http://secunia.com/advisories/56996Vendor Advisory
- http://www.securityfocus.com/bid/65953
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.