CVE Vulnerabilities

CVE-2024-57546

Insecure Storage of Sensitive Information

Published: Jan 27, 2025 | Modified: Apr 16, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

An issue in CMSimple v.5.16 allows a remote attacker to obtain sensitive information via a crafted script to the validate link function.

Weakness

The product stores sensitive information without properly limiting read or write access by unauthorized actors.

Affected Software

Name Vendor Start Version End Version
Cmsimple Cmsimple 5.16 (including) 5.16 (including)

References