PT-2025-50529 · Cmsimple · Cmsimple

Published

2025-12-10

·

Updated

2025-12-31

·

CVE-2024-58280

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions CMSimple version 5.15
Description An authenticated attacker can execute commands remotely on the server. This is possible by modifying file extensions and uploading malicious PHP files. Specifically, attackers can append ',php' to Extensions userfiles and upload a shell script to the media directory, enabling arbitrary code execution.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Weakness Enumeration

Related Identifiers

CVE-2024-58280

Affected Products

Cmsimple