ZeroHour

CVE-2024-1527

CVSS 3.1
8.8 high
EPSS
<1%p58
Published
()
Modified
Description

Unrestricted file upload vulnerability in CMS Made Simple, affecting version 2.2.14. This vulnerability allows an authenticated user to bypass the security measures of the upload functionality and potentially create a remote execution of commands via webshell.

Vendors
cmsmadesimple
Products
cms made simple
Weakness
CWE-434
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.