PHP Object Injection Vulnerability in CMS Made Simple by CMS Made Simple, Inc.
CVE-2018-10085
9.8CRITICAL
Summary
CMS Made Simple versions up to 2.2.6 are susceptible to a PHP object injection vulnerability due to improper handling of user-supplied cookies. An attacker can exploit this flaw by sending specially crafted cookies to the system. This may allow for the remote uploading and execution of malicious code or the potential deletion of files, compromising the security and integrity of the affected CMS.
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability Reserved
Vulnerability published