2025-09-29 16:08:36 +00:00
|
|
|
### [CVE-2024-57549](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-57549)
|
|
|
|
|

|
2025-09-29 21:09:30 +02:00
|
|
|

|
|
|
|
|

|
2025-09-29 16:08:36 +00:00
|
|
|
|
|
|
|
|
### Description
|
|
|
|
|
|
|
|
|
|
CMSimple 5.16 allows the user to read cms source code through manipulation of the file name in the file parameter of a GET request.
|
|
|
|
|
|
|
|
|
|
### POC
|
|
|
|
|
|
|
|
|
|
#### Reference
|
2025-09-29 21:09:30 +02:00
|
|
|
- https://github.com/h4ckr4v3n/cmsimple5.16_research/blob/main/CMSimple%205.16%20Sensitive%20information%20disclosure.md
|
2025-09-29 16:08:36 +00:00
|
|
|
|
|
|
|
|
#### Github
|
|
|
|
|
- https://github.com/h4ckr4v3n/cmsimple5.16_research
|
|
|
|
|
|