VulnerabilityModified
CVE-2017-1000454
CMS Made Simple 2.1.6, 2.2, 2.2.1 are vulnerable to Smarty Template Injection in some core components, resulting in local file read before 2.2, and local file inclusion since 2.2.1
HIGH 7.8EPSS 0.78%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.78%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
CMS Made Simple 2.1.6, 2.2, 2.2.1 are vulnerable to Smarty Template Injection in some core components, resulting in local file read before 2.2, and local file inclusion since 2.2.1
- CVSS 3.0
- 7.8 HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.78% probability · 54th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-74
- Affected
- cmsmadesimple/cms made simple
- Source
- cve@mitre.org
References
- https://www.cmsmadesimple.org/2017/07/Announcing-CMSMS-2.2.2-Hearts-ContentIssue Tracking, Vendor Advisory
- https://www.cmsmadesimple.org/2017/07/Announcing-CMSMS-2.2.2-Hearts-ContentIssue Tracking, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.