Vulnerability Description
In CMS Made Simple (CMSMS) before 2.2.10, an authenticated user can achieve SQL Injection in class.showtime2_data.php via the functions _updateshow (parameter show_id), _inputshow (parameter show_id), _Getshowinfo (parameter show_id), _Getpictureinfo (parameter picture_id), _AdjustNameSeq (parameter shownumber), _Updatepicture (parameter picture_id), and _Deletepicture (parameter picture_id).
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cmsmadesimple | Cms Made Simple | < 2.2.10 |
Related Weaknesses (CWE)
References
- http://viewsvn.cmsmadesimple.org/diff.php?repname=showtime2&path=%2Ftrunk%2Flib%Patch
- https://forum.cmsmadesimple.org/viewtopic.php?f=1&t=80285Vendor Advisory
- http://viewsvn.cmsmadesimple.org/diff.php?repname=showtime2&path=%2Ftrunk%2Flib%Patch
- https://forum.cmsmadesimple.org/viewtopic.php?f=1&t=80285Vendor Advisory
FAQ
What is CVE-2019-9693?
CVE-2019-9693 is a vulnerability with a CVSS score of 8.8 (HIGH). In CMS Made Simple (CMSMS) before 2.2.10, an authenticated user can achieve SQL Injection in class.showtime2_data.php via the functions _updateshow (parameter show_id), _inputshow (parameter show_id),...
How severe is CVE-2019-9693?
CVE-2019-9693 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-9693?
Check the references section above for vendor advisories and patch information. Affected products include: Cmsmadesimple Cms Made Simple.