PHP Object Injection Vulnerability in CMS Made Simple by CMS Made Simple, Inc.
CVE-2018-10085

9.8CRITICAL

Key Information:

Vendor
CVE Published:
13 April 2018

Summary

CMS Made Simple versions up to 2.2.6 are susceptible to a PHP object injection vulnerability due to improper handling of user-supplied cookies. An attacker can exploit this flaw by sending specially crafted cookies to the system. This may allow for the remote uploading and execution of malicious code or the potential deletion of files, compromising the security and integrity of the affected CMS.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability Reserved

  • Vulnerability published

.