An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve unauthenticated blind time-based SQL injection via the m1_idlist parameter.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 17 Nov 2025 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-11-17T19:19:52.125Z
Reserved: 2019-02-23T00:00:00.000Z
Link: CVE-2019-9053
No data.
Status : Modified
Published: 2019-03-26T17:29:01.420
Modified: 2025-11-17T20:15:48.813
Link: CVE-2019-9053
No data.
OpenCVE Enrichment
No data.