vendor:
CMS Made Simple
by:
EgiX
7.5
CVSS
HIGH
Remote SQL Injection
89
CWE
Product Name: CMS Made Simple
Affected Version From: 1
Affected Version To: 1.2.2002
Patch Exists: NO
Related CWE:
CPE: cms_made_simple:cms_made_simple:1.2.2
Platforms Tested:
2007
CMS Made Simple <= 1.2.2 (TinyMCE module) - Remote SQL Injection Advisory
The vulnerability exists in the 'content_css.php' file of the TinyMCE module in CMS Made Simple <= 1.2.2. The 'templateid' parameter is not properly checked, allowing an attacker to inject SQL code at line 67. This can be exploited to extract sensitive data from the database.
Mitigation:
Update CMS Made Simple to a version higher than 1.2.2.