vendor:
CMS Made Simple
by:
Lucian Ioan Nitescu
7.2
CVSS
HIGH
Remote Code Execution
78
CWE
Product Name: CMS Made Simple
Affected Version From: 2.2.7
Affected Version To: 2.2.7
Patch Exists: YES
Related CWE: CVE-2018-10517
CPE: 2.2.7
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Ubuntu 18.04
2018
CMS Made Simple 2.2.7 – Remote Code Execution
An attacker or a malicious user with access to the administration interface can execute code on the server. After the plugin is uploaded, an attacker can execute arbitrary code on the server by accessing the URL http://<TARGET_URL>/tmp/test.php?cmd=<COMMAND>
Mitigation:
Ensure that the CMS Made Simple version is up to date and that all plugins are updated to the latest version.