CVE-2018-10519
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
CMS Made Simple (CMSMS) 2.2.7 contains a privilege escalation vulnerability from ordinary user to admin user by arranging for the eff_uid value within $_COOKIE[$this->_loginkey] to equal 1, because files in the tmp/ directory are accessible through HTTP requests. NOTE: this vulnerability exists because of an incorrect fix for CVE-2018-10084.
CMS Made Simple (CMSMS) 2.2.7 contiene una vulnerabilidad de escalado de privilegios de usuario ordinario a usuario administrador haciendo que el valor de eff_uid en $_COOKIE[$this->_loginkey] sea igual a 1. Esto se debe a que se puede acceder a los archivos en el directorio tmp/ mediante peticiones HTTP. NOTA: Esta vulnerabilidad existe debido a una soluciĆ³n incorrecta para CVE-2018-10084.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2018-04-27 CVE Reserved
- 2018-04-27 CVE Published
- 2024-09-16 CVE Updated
- 2024-09-16 First Exploit
- 2024-09-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-732: Incorrect Permission Assignment for Critical Resource
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://github.com/itodaro/cmsms_cve/blob/master/README.md | 2024-09-16 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Cmsmadesimple Search vendor "Cmsmadesimple" | Cms Made Simple Search vendor "Cmsmadesimple" for product "Cms Made Simple" | 2.2.7 Search vendor "Cmsmadesimple" for product "Cms Made Simple" and version "2.2.7" | - |
Affected
|