Authenticated Object Injection in CMS Made Simple 2.2.8 FilePicker Module

Authenticated Object Injection in CMS Made Simple 2.2.8 FilePicker Module

CVE-2019-9057 · HIGH Severity

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

An issue was discovered in CMS Made Simple 2.2.8. In the module FilePicker, it is possible to reach an unserialize call with an untrusted parameter, and achieve authenticated object injection.

Learn more about our Cms Pen Testing.