PT-2025-46221 · Unknown · Cms Made Simple Foundation File Manager

Published

2025-11-10

·

Updated

2025-12-31

·

CVE-2025-63678

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions CMS Made Simple Foundation File Manager version 2.2.22
Description An authenticated arbitrary file upload issue exists in the /uploads/ endpoint of the software. An attacker with Administrator privileges can upload a crafted PHP file, potentially leading to arbitrary code execution.
Recommendations Update to a newer version that contains a fix for this vulnerability. As a temporary workaround, restrict file uploads to authorized users only.

Exploit

Fix

RCE

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2025-63678

Affected Products

Cms Made Simple Foundation File Manager