CVE-2019-9053 | CMS Made Simple up to 2.2.8 News m1_idlist Time-Based sql injection (ID 152356 / EDB-46635)
A vulnerability categorized as critical has been discovered in CMS Made Simple up to 2.2.8. Affected by this vulnerability is an unknown functionality of the component News Module. The manipulation of the argument m1_idlist as part of Parameter results in sql injection (Time-Based).
This vulnerability is reported as CVE-2019-9053. The attack can be launched remotely. Moreover, an exploit is present.