PT-2017-18617 · Cms Made Simple · Cms Made Simple
Osanda Malith Jayathissa
+1
·
Publicado
2017-05-12
·
Atualizado
2024-08-05
·
CVE-2017-8912
CVSS v3.1
7.2
Alta
| Vetor | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
CMS Made Simple version 2.1.6
Description
The issue allows remote authenticated administrators to execute arbitrary PHP code via the
code parameter to "admin/editusertag.php", related to the CreateTagFunction and CallUserTag functions. The vendor has reportedly stated that this behavior is considered "a feature, not a bug."Recommendations
For CMS Made Simple version 2.1.6, consider disabling access to the "admin/editusertag.php" endpoint or restricting the use of the
code parameter to prevent arbitrary PHP code execution until a resolution is provided by the vendor.Exploit
Correção
Code Injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Cms Made Simple