CVE-2019-9053 — Cms Made Simple
HIGHCVE-2019-9053 is a high-severity (CVSS 8.1) SQL Injection vulnerability in cmsmadesimple cms made simple. 25 public exploit references exist, so weaponization risk is real. No vendor fix is recorded yet; mitigation options are listed below.
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve unauthenticated blind time-based SQL injection via the m1_idlist parameter.
EPSS Exploitation Probability
Probability of exploitation in the next 30 days, from FIRST.org EPSS.
How urgent is this, really
CVE-2019-9053 by exploitation likelihood (EPSS) against impact (CVSS). In the shaded patch-first corner (EPSS 50%+, CVSS 7.0+).
Where this sits among everything scored
Of 385,386 CVEs with a current EPSS score, this one falls in the 50–90% band (highlighted). Counts from FIRST.org, log-scaled.
Description
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve unauthenticated blind time-based SQL injection via the m1_idlist parameter.
Affected Products
cms made simplecmsmadesimpleResearch use only. For defensive security, authorized penetration testing, and academic research only. Never execute exploit code against systems without explicit written authorization.
CMS Made Simple < 2.2.10 - SQL Injection
by Daniele Scanu · Apr 2, 2019
Detection & mitigation playbook
Vendor / applianceDetect
Inventory every cmsmadesimple cms made simple deployment and check each version against the affected-products list above.
Remediation status
No patch has shipped for CVE-2019-9053 yet — track the cmsmadesimple cms made simple advisory for a fixed release and apply the workarounds below in the meantime.
Mitigate without a patch
Until you can upgrade, make sure every query built from user input uses parameterised statements or a prepared-statement API rather than string concatenation, and reduce the database account's privileges so an injected query cannot read or alter data beyond what the feature needs. Alongside that, restrict the management interface to trusted networks and apply the vendor's recommended configuration mitigations.
Frequently Asked Questions
Is CVE-2019-9053 being exploited in your environment?
Detect and block the exploit chain at execution, on systems you cannot patch yet.