vendor:
CMS Made Simple
by:
Gurkirat Singh
9.8
CVSS
CRITICAL
Server-Side Template Injection
94
CWE
Product Name: CMS Made Simple
Affected Version From: 2.1.6
Affected Version To: 2.1.6
Patch Exists: YES
Related CWE: CVE-2017-16783
CPE: 2.1.6
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Linux
2017
CMS Made Simple 2.1.6 – ‘cntnt01detailtemplate’ Server-Side Template Injection
CMS Made Simple 2.1.6 is vulnerable to Server-Side Template Injection. An attacker can inject malicious code into the 'cntnt01detailtemplate' parameter of the vulnerable application and execute arbitrary commands on the server.
Mitigation:
The application should validate user input and filter out any malicious code before processing it.