CVE Vulnerabilities

CVE-2024-57546

Insecure Storage of Sensitive Information

Published: Jan 27, 2025 | Modified: Apr 16, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

An issue in CMSimple v.5.16 allows a remote attacker to obtain sensitive information via a crafted script to the validate link function.

Weakness

The product stores sensitive information without properly limiting read or write access by unauthorized actors.

Affected Software

NameVendorStart VersionEnd Version
CmsimpleCmsimple5.16 (including)5.16 (including)

References