PHP Object Injection Vulnerability in CMS Made Simple by CMS Made Simple, Inc.
CVE-2018-10085
9.8CRITICAL
What is CVE-2018-10085?
CMS Made Simple versions up to 2.2.6 are susceptible to a PHP object injection vulnerability due to improper handling of user-supplied cookies. An attacker can exploit this flaw by sending specially crafted cookies to the system. This may allow for the remote uploading and execution of malicious code or the potential deletion of files, compromising the security and integrity of the affected CMS.