Описание
CMSimple 5.4 contains an authenticated remote code execution vulnerability that allows logged-in attackers to inject malicious PHP code into template files. Attackers can exploit the template editing functionality by crafting a reverse shell payload and saving it through the template editing endpoint with a valid CSRF token.
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:cmsimple:cmsimple:5.4:*:*:*:*:*:*:*
EPSS
Процентиль: 51%
0.00285
Низкий
8.8 High
CVSS3
Дефекты
CWE-94
Связанные уязвимости
CVSS3: 8.8
github
около 2 месяцев назад
CMSimple 5.4 contains an authenticated remote code execution vulnerability that allows logged-in attackers to inject malicious PHP code into template files. Attackers can exploit the template editing functionality by crafting a reverse shell payload and saving it through the template editing endpoint with a valid CSRF token.
EPSS
Процентиль: 51%
0.00285
Низкий
8.8 High
CVSS3
Дефекты
CWE-94