Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-c585-x36v-3ppq

Опубликовано: 14 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.2

Описание

In CMS Made Simple (CMSMS) through 2.2.7, the "module import" operation in the admin dashboard contains a remote code execution vulnerability, exploitable by an admin user, because an XML Package can contain base64-encoded PHP code in a data element.

In CMS Made Simple (CMSMS) through 2.2.7, the "module import" operation in the admin dashboard contains a remote code execution vulnerability, exploitable by an admin user, because an XML Package can contain base64-encoded PHP code in a data element.

EPSS

Процентиль: 95%
0.17792
Средний

7.2 High

CVSS3

Дефекты

CWE-94

Связанные уязвимости

CVSS3: 7.2
nvd
почти 8 лет назад

In CMS Made Simple (CMSMS) through 2.2.7, the "module import" operation in the admin dashboard contains a remote code execution vulnerability, exploitable by an admin user, because an XML Package can contain base64-encoded PHP code in a data element.

EPSS

Процентиль: 95%
0.17792
Средний

7.2 High

CVSS3

Дефекты

CWE-94