CVE-2024-57549

CMSimple 5.16 allows the user to read cms source code through manipulation of the file name in the file parameter of a GET request.
Configurations

Configuration 1 (hide)

cpe:2.3:a:cmsimple:cmsimple:5.16:*:*:*:*:*:*:*

History

11 Apr 2025, 19:04

Type Values Removed Values Added
CPE cpe:2.3:a:cmsimple:cmsimple:5.16:*:*:*:*:*:*:*
Summary
  • (es) CMSimple 5.16 permite al usuario leer el código fuente de CMS mediante la manipulación del nombre del archivo en el parámetro de archivo de una solicitud GET.
First Time Cmsimple cmsimple
Cmsimple
References () https://gist.github.com/h4ckr4v3n/afbb87b5a05f283dbee705709c2769eb - () https://gist.github.com/h4ckr4v3n/afbb87b5a05f283dbee705709c2769eb - Third Party Advisory
References () https://github.com/h4ckr4v3n/cmsimple5.16_research/blob/main/CMSimple%205.16%20Sensitive%20information%20disclosure.md - () https://github.com/h4ckr4v3n/cmsimple5.16_research/blob/main/CMSimple%205.16%20Sensitive%20information%20disclosure.md - Exploit, Third Party Advisory

28 Jan 2025, 20:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
CWE CWE-22

27 Jan 2025, 23:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-27 23:15

Updated : 2025-04-11 19:04


NVD link : CVE-2024-57549

Mitre link : CVE-2024-57549

CVE.ORG link : CVE-2024-57549


JSON object : View

Products Affected

cmsimple

  • cmsimple
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')