ZeroHour

CVE-2017-1000453

CVSS 3.0
9.8 critical
EPSS
2%p77
Published
()
Modified
Description

CMS Made Simple version 2.1.6 and 2.2 are vulnerable to Smarty templating injection in some core modules, resulting in unauthenticated PHP code execution.

Vendors
cmsmadesimple
Products
cms made simple
Weakness
CWE-74
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.