In CMS Made Simple 2.2.8, the DesignManager module (specifically in action.admin_bulk_css.php and action.admin_bulk_template.php) allows an unprivileged user with Designer permissions to supply crafted input to the m1_allparms parameter, which is then passed to an unserialize() call. This enables PHP object injection, potentially allowing arbitrary code execution depending on available classes and magic methods.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a single Metasploit module (Ruby file) that exploits an authenticated object injection vulnerability (CVE-2019-9055) in CMS Made Simple versions up to 2.2.9.1. The exploit targets the DesignManager module, specifically the 'm1_allparms' parameter, to trigger a PHP object injection via a crafted serialized payload. The attacker must have valid credentials for a user with 'Designer' permissions. The module authenticates to the CMS, crafts a malicious serialized object that executes arbitrary PHP code (by writing a webshell), and then accesses the webshell to achieve remote code execution. The main endpoints involved are the admin login, module interface, and the location where the webshell is written. The exploit is operational, as it provides a working payload and automates the attack process, but is not fully weaponized (payload customization is possible but not as flexible as a full framework module with extensive options).
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.