CMSimple 5.16 allows the user to edit log.php file via print page.
The vulnerability results from improperly configured access permissions (CWE-276 — Incorrect Default Permissions). The print page function in CMSimple 5.16 does not properly restrict access to editing the log.php file. An unauthenticated attacker using network access to the application can modify the contents of this file.
An attacker can gain unauthorized write access to the log.php file, which potentially leads to data integrity violation and disclosure of sensitive information stored in the application logs.
Patches available from the manufacturer should be applied in accordance with the references. It is also recommended to restrict access to sensitive administrative functions of the application at the web server level or firewall until updates are deployed.
CMSimple version 5.16
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:NCmsimple
APPCmsimple5.16
Related vulnerabilities
CMSimple 5.4 — path traversal prowadzący do RCE przez config.php
CMSimple 5.4 contains an authenticated local file inclusion vulnerability that allows remote attackers to mani...
CMSimple 5.4 contains an authenticated remote code execution vulnerability that allows logged-in attackers to ...
CMSimple 5.15 contains a remote command execution vulnerability that allows authenticated attackers to modify ...
An issue in CMSimple v.5.16 allows a remote attacker to obtain sensitive information via a crafted script to t...