CVE-2018-10084

Severity CVSS v4.0:
Pending analysis
Type:
CWE-327 Use of a Broken or Risky Cryptographic Algorithm
Publication date:
13/04/2018
Last modified:
03/10/2019

Description

CMS Made Simple (CMSMS) through 2.2.6 contains a privilege escalation vulnerability from ordinary user to admin user by arranging for the eff_uid value within $_COOKIE[$this->_loginkey] to equal 1, because an SHA-1 cryptographic protection mechanism can be bypassed.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:cmsmadesimple:cms_made_simple:*:*:*:*:*:*:*:* 2.2.6 (including)


References to Advisories, Solutions, and Tools