CMS Made Simple (CMSMS) before 2.2.5 does not properly cache login information in cookies.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://forum.cmsmadesimple.org/viewtopic.php?f=1&t=77737 | issue tracking vendor advisory |
https://www.cmsmadesimple.org/2017/12/Announcing-CMSMS-v2.2.5-Wawa | issue tracking vendor advisory |