vendor:
CmsMadeSimple
by:
Mirabbas Agalarov
8.6
CVSS
HIGH
Session Hijacking
613
CWE
Product Name: CmsMadeSimple
Affected Version From: v2.2.17
Affected Version To: v2.2.17
Patch Exists: NO
Related CWE:
CPE: cmsmadesimple
Platforms Tested: Linux
2023
CmsMadeSimple v2.2.17 – session hijacking via Server-Side Template Injection (SSTI)
The CmsMadeSimple v2.2.17 application is vulnerable to session hijacking through Server-Side Template Injection (SSTI). An attacker can inject malicious code into the content section, which can be executed when a user visits the page. This allows the attacker to hijack the user's session cookies.
Mitigation:
To mitigate this vulnerability, it is recommended to update CmsMadeSimple to the latest version and apply any available patches. Additionally, users should be cautious when visiting websites and ensure they are using secure connections (HTTPS) to prevent session hijacking.