Authenticated Object Injection in CMS Made Simple 2.2.8 FilePicker Module
CVE-2019-9057 · HIGH Severity
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
An issue was discovered in CMS Made Simple 2.2.8. In the module FilePicker, it is possible to reach an unserialize call with an untrusted parameter, and achieve authenticated object injection.
Learn more about our Cms Pen Testing.