CVE-2014-2245: Cmsmadesimple CMS Made Simple
Medium severity, CVSS 6.0. EPSS: 1% chance of exploitation in the next 30 days.
SQL injection vulnerability in the News module in CMS Made Simple (CMSMS) before 1.11.10 allows remote authenticated users with the "Modify News" permission to execute arbitrary SQL commands via the sortby parameter to admin/moduleinterface.php. NOTE: some of these details are obtained from third party information.
Affected products
- Cmsmadesimple CMS Made Simple: up to and including 1.11.9; version 0.1 only; version 0.2 only; version 0.2.1 only; version 0.3 only; version 0.3.1 only; …
Published 2014-03-05. Last modified 2026-06-17.