PT-2024-21973 · Unknown · Cms Made Simple
Tmrswrr
·
Published
2024-03-05
·
Updated
2025-12-17
·
CVE-2024-27623
CVSS v3.1
5.9
Medium
| Vector | AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
CMS Made Simple version 2.2.19
Description
The issue is related to Server-Side Template Injection (SSTI) within the Design Manager, specifically when editing the Breadcrumbs.
Recommendations
For CMS Made Simple version 2.2.19, consider disabling the editing functionality of the Breadcrumbs in the Design Manager until a patch is available. Restrict access to the Design Manager to minimize the risk of exploitation.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cms Made Simple