← back
CVE-2019-9055

CVE-2019-9055

23Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendepss 12%
from disclosure to weapon0 days
Published on NVDMar 26
metasploitMar 26
exploitation probability
12%top 4% of all CVEs
observed exploitation
nono source reports it
An issue was discovered in CMS Made Simple 2.2.8. In the module DesignManager (in the files action.admin_bulk_css.php and action.admin_bulk_template.php), with an unprivileged user with Designer permission, it is possible reach an unserialize call with a crafted value in the m1_allparms parameter, and achieve object injection.
Affected products
n/a · n/a