peter bassill · operator
$ cve CVE-2018-10085 JSON

CVE-2018-10085

9.8
CRITICAL · CVSS 3.0 · EPSS 3.8% (pctl 90)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

CMS Made Simple (CMSMS) through 2.2.6 allows PHP object injection because of an unserialize call in the _get_data function of \lib\classes\internal\class.LoginOperations.php. By sending a crafted cookie, a remote attacker can upload and execute code, or delete files.

Scoring

CVSS9.8 (CRITICAL, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS3.79% — more likely to be exploited than 90% of all CVEs
WeaknessCWE-502
On CISA KEVno
Public exploitnone known
Published2018-04-13
Last modified2026-06-17

Affected (1)

VendorProduct
cmsmadesimplecms made simple

References

→ the Explorer  ·  watch your stack  ·  NVD