CVE-2024-1527

Published Mar 12, 2024

Last updated a year ago

Overview

Description
Unrestricted file upload vulnerability in CMS Made Simple, affecting version 2.2.14. This vulnerability allows an authenticated user to bypass the security measures of the upload functionality and potentially create a remote execution of commands via webshell.
Source
cve-coordination@incibe.es
NVD status
Analyzed
Products
cms_made_simple

Risk scores

CVSS 3.1

Type
Primary
Base score
8.8
Impact score
5.9
Exploitability score
2.8
Vector string
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Severity
HIGH

Weaknesses

cve-coordination@incibe.es
CWE-434

Social media

Hype score
Not currently trending

Configurations