Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
An issue was discovered in CMS Made Simple 2.2.8. It is possible to achieve unauthenticated path traversal in the CGExtensions module (in the file action.setdefaulttemplate.php) with the m1_filename parameter; and through the action.showmessage.php file, it is possible to read arbitrary file content (by using that path traversal with m1_prefname set to cg_errormsg and m1_resettodefault=1).
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
CMS Made Simple 路径遍历漏洞
Vulnerability Description
CMS Made Simple(CMSMS)是CMSMS(Cmsms)团队的一套开源的内容管理系统(CMS)。该系统支持基于角色的权限管理系统、基于向导的安装与更新机制、智能缓存机制等。 CMS Made Simple 中存在路径遍历漏洞,该漏洞源于产品CGExtensions模块action.setdefaulttemplate.php文件中的m1_filename参数未能添加有效的权限验证以及输入验证。攻击者可在未身份验证的前提下遍历路径以及读取任意文件内容。 以下产品及版本受到影响: CMS Mad
CVSS Information
N/A
Vulnerability Type
N/A