ZeroHour

CVE-2017-1000454

CVSS 3.0
7.8 high
EPSS
<1%p54
Published
()
Modified
Description

CMS Made Simple 2.1.6, 2.2, 2.2.1 are vulnerable to Smarty Template Injection in some core components, resulting in local file read before 2.2, and local file inclusion since 2.2.1

Vendors
cmsmadesimple
Products
cms made simple
Weakness
CWE-74
Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.