CRITICAL🇵🇱 Wersja polska

CVE-2024-57548

CVSS 9.1v3.1pub. 2025-01-27upd. 2025-04-11

CMSimple 5.16 allows the user to edit log.php file via print page.

🤖 AI Analysis
How it works

The vulnerability results from improperly configured access permissions (CWE-276 — Incorrect Default Permissions). The print page function in CMSimple 5.16 does not properly restrict access to editing the log.php file. An unauthenticated attacker using network access to the application can modify the contents of this file.

Impact

An attacker can gain unauthorized write access to the log.php file, which potentially leads to data integrity violation and disclosure of sensitive information stored in the application logs.

Mitigation & patch

Patches available from the manufacturer should be applied in accordance with the references. It is also recommended to restrict access to sensitive administrative functions of the application at the web server level or firewall until updates are deployed.

Who is affected

CMSimple version 5.16

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
  • Cmsimple

    APP
    Cmsimple
    5.16
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2021-43741CRITICAL9.8PL ✓same product

CMSimple 5.4 — path traversal prowadzący do RCE przez config.php

CVE-2021-47734HIGH8.6same product

CMSimple 5.4 contains an authenticated local file inclusion vulnerability that allows remote attackers to mani...

CVE-2021-47735HIGH8.6same product

CMSimple 5.4 contains an authenticated remote code execution vulnerability that allows logged-in attackers to ...

CVE-2024-58280HIGH8.6same product

CMSimple 5.15 contains a remote command execution vulnerability that allows authenticated attackers to modify ...

CVE-2024-57546HIGH7.5same product

An issue in CMSimple v.5.16 allows a remote attacker to obtain sensitive information via a crafted script to t...