Vulnerability record · CVE-2019-9053 · published 26 March 2019
CVE-2019-9053: CMS Made Simple News module unauthenticated blind SQL injection
Cmsmadesimple · Cms Made Simple
CMS Made Simple 2.2.8 is vulnerable to unauthenticated blind time-based SQL injection in the News module via the m1_idlist parameter in a crafted URL. The flaw allows an attacker to inject SQL into backend queries without logging in, which matters because it exposes the site's database contents and can lead to full compromise of the CMS.
Description
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve unauthenticated blind time-based SQL injection via the m1_idlist parameter.
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityUnauthenticated remote SQL injection with public exploit code and very high EPSS probability, though not listed in KEV.
What it is
CMS Made Simple 2.2.8 is vulnerable to unauthenticated blind time-based SQL injection in the News module via the m1_idlist parameter in a crafted URL. The flaw allows an attacker to inject SQL into backend queries without logging in, which matters because it exposes the site's database contents and can lead to full compromise of the CMS.
Impact
An attacker can extract arbitrary data from the underlying database, including CMS user credentials and content, and may be able to modify or destroy data depending on database privileges. This can lead to administrative account takeover and full site compromise.
Attack surface
Reachable remotely over HTTP through the News module by supplying a crafted m1_idlist parameter; no authentication or user interaction is required per the CVSS vector (PR:N, UI:N).
Exploitation
Public exploit code exists (Exploit-DB 46635 and Packet Storm references), and EPSS is 0.68581 (99.3rd percentile), indicating high likelihood of exploitation; the CVE is not listed in CISA KEV.
What to do
- Upgrade CMS Made Simple to 2.2.10 or later, which the vendor advisory identifies as the fixed release.
- If immediate upgrade is not possible, disable or remove the News module until patched.
- Deploy a WAF rule to block SQL injection patterns targeting the m1_idlist parameter.
- Restrict database account privileges used by the CMS to the minimum required.
- Audit CMS user accounts and rotate credentials in case of prior compromise.
Detection
- Monitor web server logs for requests to News module URLs containing suspicious m1_idlist values, especially SQL keywords, quotes, or time-delay functions.
- Look for repeated requests with time-delay payloads (e.g., SLEEP, BENCHMARK) that produce unusually long response times.
- Alert on database errors or anomalous query patterns originating from the web application.
- Review CMS logs and file integrity for signs of post-exploitation activity following SQL injection attempts.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/152356/CMS-Made-Simple-SQL-Injection.html | ExploitThird Party AdvisoryVDB Entry |
| https://github.com/Perseus99999/CVE-2019-9053-working-/blob/main/exploit.py | |
| https://newsletter.cmsmadesimple.org/w/89247Qog4jCRCuRinvhsofwg | Release NotesVendor Advisory |
| https://www.cmsmadesimple.org/2019/03/Announcing-CMS-Made-Simple-v2.2.10-Spuzzum | Release NotesVendor Advisory |
| https://www.exploit-db.com/exploits/46635/ | ExploitThird Party AdvisoryVDB Entry |
| http://packetstormsecurity.com/files/152356/CMS-Made-Simple-SQL-Injection.html | ExploitThird Party AdvisoryVDB Entry |
| https://newsletter.cmsmadesimple.org/w/89247Qog4jCRCuRinvhsofwg | Release NotesVendor Advisory |
| https://www.cmsmadesimple.org/2019/03/Announcing-CMS-Made-Simple-v2.2.10-Spuzzum | Release NotesVendor Advisory |
| https://www.exploit-db.com/exploits/46635/ | ExploitThird Party AdvisoryVDB Entry |
Track CVE-2019-9053 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-9053), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.