CVE-2018-1000094
CMS Made Simple version 2.2.5 contains a Remote Code Execution vulnerability in File Manager that can result in Allows an authenticated admin that has access to the file manager to execute code on the server.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 38.8%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
CMS Made Simple version 2.2.5 contains a Remote Code Execution vulnerability in File Manager that can result in Allows an authenticated admin that has access to the file manager to execute code on the server. This attack appear to be exploitable via File upload -> copy to any extension.
- CVSS 3.0
- 7.2 HIGHCVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 38.80% probability · 99th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-434
- Affected
- cmsmadesimple/cms made simple
- Source
- cve@mitre.org
References
- http://dev.cmsmadesimple.org/bug/view/11741Exploit, Issue Tracking, Vendor Advisory
- https://www.exploit-db.com/exploits/44976/Exploit, Third Party Advisory, VDB Entry
- http://dev.cmsmadesimple.org/bug/view/11741Exploit, Issue Tracking, Vendor Advisory
- https://www.exploit-db.com/exploits/44976/Exploit, Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.