PoC Index

CVE-2018-1000094

HIGH 7.2EPSS 38.8%

CMS Made Simple version 2.2.5 contains a Remote Code Execution vulnerability in File Manager that can result in Allows an authenticated admin that has access to the file manager to execute code on the server. This attack appear to be exploitable via File upload -> copy to any extension.

CVSS v3.0
7.2 HIGHCVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0
6.5 MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
EPSS
38.80% chance of exploitation in the next 30 days, 98th percentile
Published
2018-03-13
Updated
2024-08-05

Proof-of-concept exploits (1)

Metasploit modules (1)

ExploitDB entries (1)

References

Related