CVE-2019-9060
It is possible to achieve unauthenticated path traversal in the CGExtensions module (in the file action.setdefaulttemplate.php) with the m1_filename parameter; and through the action.showmessage.php file, it is possible to read arbitrary file content…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.51%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
An issue was discovered in CMS Made Simple 2.2.8. It is possible to achieve unauthenticated path traversal in the CGExtensions module (in the file action.setdefaulttemplate.php) with the m1_filename parameter; and through the action.showmessage.php file, it is possible to read arbitrary file content (by using that path traversal with m1_prefname set to cg_errormsg and m1_resettodefault=1).
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 1.51% probability · 73th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22
- Affected
- cmsmadesimple/cms made simple
- Source
- cve@mitre.org
References
- http://dev.cmsmadesimple.org/project/changelog/5819Release Notes, Vendor Advisory
- https://forum.cmsmadesimple.org/viewtopic.php?f=1&t=80285Vendor Advisory
- https://newsletter.cmsmadesimple.org/w/89247Qog4jCRCuRinvhsofwgVendor Advisory
- https://www.cmsmadesimple.org/2019/03/Announcing-CMS-Made-Simple-v2.2.10-SpuzzumVendor Advisory
- http://dev.cmsmadesimple.org/project/changelog/5819Release Notes, Vendor Advisory
- https://forum.cmsmadesimple.org/viewtopic.php?f=1&t=80285Vendor Advisory
- https://newsletter.cmsmadesimple.org/w/89247Qog4jCRCuRinvhsofwgVendor Advisory
- https://www.cmsmadesimple.org/2019/03/Announcing-CMS-Made-Simple-v2.2.10-SpuzzumVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.