CVE-2019-9053

high

Description

An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve unauthenticated blind time-based SQL injection via the m1_idlist parameter.

References

https://github.com/Jeanback1/exploit-vault

https://github.com/Vedantrana73/cve-2019-9053-py3

https://github.com/rgkue/mysqli

https://github.com/Jeanback1/CVE-2019-9053-exploit

https://github.com/ImperialX1104/Simple-CTF-Writeup

https://github.com/v4rr10r/CVE-2019-9053

https://github.com/jyothsna-Git007/CMS-Made-Simple-2.2.10---SQL-Injection

https://github.com/paulameg/SimpleCTF-THM-Relatory

https://github.com/killukeren/-CVE-2019-9053

https://github.com/coolkiee/CVE-2019-9053

https://github.com/iTzR1g/CVE-2019-9053

https://github.com/pasan2002/CVE-2019-9053---CMS-Made-Simple-SQL-Injection-Exploit-Modified-

https://github.com/tim-karov/cmsms-sqli

https://github.com/Praditha29/Simple-CTF-THM-Writeup

https://github.com/Perseus99999/CVE-2019-9053-working-

https://github.com/JagdeepSinghCeh/cms-made-simple-python3

https://github.com/pwnk1t/cve-collection

https://github.com/CaelumIsMe/CVE-2019-9053-POC

https://github.com/Slayerma/-CVE-2019-9053

https://github.com/noob-hacker572/CMS-Made-Simple-2.2.9-CVE-2019-9053

https://github.com/uttambodara/Awesome-Hacking-Learning-Path

https://github.com/Hackheart-tech/-exploit-lab

https://github.com/kaizoku73/CVE-2019-9053

https://github.com/del0x3/CVE-2019-9053-port-py3

https://github.com/so1icitx/CVE-2019-9053

https://github.com/hf3cyber/CMS-Made-Simple-2.2.9-Unauthenticated-SQL-Injection-Exploit-CVE-2019-9053-

https://github.com/louisthedonothing/CVE-2019-9053

https://github.com/Azrenom/CMS-Made-Simple-2.2.9-CVE-2019-9053

https://github.com/jtoalu/CTF-CVE-2019-9053-GTFOBins

https://github.com/TeymurNovruzov/CVE-2019-9053-python3-remastered

https://github.com/Dh4nuJ4/SimpleCTF-UpdatedExploit

https://github.com/GandalfShark/simpleCTF

https://github.com/davcwikla/CVE-2019-9053-exploit

https://github.com/im-suman-roy/CVE-2019-9053

https://github.com/AppyAppy/super-octo-carnival

https://github.com/pedrojosenavasperez/CVE-2019-9053-Python3

https://github.com/zmiddle/Simple_CMS_SQLi

https://github.com/xtafnull/CMS-made-simple-sqli-python3

https://github.com/e-renna/CVE-2019-9053

https://github.com/4nner/CVE-2019-9053

https://github.com/BernieLane/CMS-Made-Simple-SQLi

https://github.com/maraspiras/46635.py

https://github.com/Marbocatcat/46635.py

https://www.exploit-db.com/exploits/46635/

https://www.cmsmadesimple.org/2019/03/Announcing-CMS-Made-Simple-v2.2.10-Spuzzum

https://newsletter.cmsmadesimple.org/w/89247Qog4jCRCuRinvhsofwg

https://github.com/Perseus99999/CVE-2019-9053-working-/blob/main/exploit.py

http://packetstormsecurity.com/files/152356/CMS-Made-Simple-SQL-Injection.html

Details

Source: Mitre, NVD

Published: 2019-03-26

Updated: 2026-06-17

Risk Information

CVSS v2

Base Score: 6.8

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P

Severity: Medium

CVSS v3

Base Score: 8.1

Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Severity: High

EPSS

EPSS: 0.68581