6.5
CVE-2007-5441
- EPSS 1.11%
- Veröffentlicht 14.10.2007 18:17:00
- Zuletzt bearbeitet 16.06.2026 22:46:09
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
CMS Made Simple 1.1.3.1 does not check the permissions assigned to users in some situations, which allows remote authenticated users to perform some administrative actions, as demonstrated by (1) adding a user via a direct request to admin/adduser.php and (2) reading the admin log via an "admin/adminlog.php?page=1" request.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Cmsmadesimple ≫ Cms Made Simple Version1.1.3.1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.11% | 0.616 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 6.5 | 8 | 6.4 |
AV:N/AC:L/Au:S/C:P/I:P/A:P
|
http://blog.cmsmadesimple.org/2007/10/07/announcing-cms-made-simple-1141/
http://osvdb.org/45481
http://securityreason.com/securityalert/3223
http://www.securityfocus.com/archive/1/481984/100/0/threaded