vendor:
Cmsimple
by:
pussycat0x
9,8
CVSS
HIGH
Remote Code Execution (RCE)
78
CWE
Product Name: Cmsimple
Affected Version From: 5.4
Affected Version To: 5.4
Patch Exists: YES
Related CWE: N/A
CPE: a:cmsimple:cmsimple:5.4
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Ubuntu-20.04.1
2021
Cmsimple 5.4 – Remote Code Execution (RCE) (Authenticated)
A vulnerability in Cmsimple 5.4 allows an authenticated user to execute arbitrary code on the target system. This is achieved by sending a crafted POST request to the target system with a malicious payload. The payload is then executed on the target system.
Mitigation:
Ensure that all users have strong passwords and that the application is kept up to date with the latest security patches.