Command Injection Vulnerability in CMS Made Simple by CMS Made Simple
CVE-2019-9059
7.2HIGH
What is CVE-2019-9059?
A vulnerability in CMS Made Simple allows an attacker with an administrator account to perform command injection. By altering the path of the e-mail executable in the Mail Settings and configuring 'sendmail' under the 'Mailer' option, an attacker can exploit the 'Forgot your password' feature to execute arbitrary commands on the server.