SB2018021702 - Remote code execution in CMS Made Simple



SB2018021702 - Remote code execution in CMS Made Simple

Published: February 17, 2018

Security Bulletin ID SB2018021702
CSH Severity
High
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Command injection (CVE-ID: CVE-2018-1000094)

The vulnerability allows a remote administrative attacker to execute arbitrary commands on the target system.

The vulnerability exists in the File Manager interface of CMS Made Simple due to insufficient validation of user-supplied input. A remote attacker can upload a malicious file, inject arbitrary commands and execute arbitrary code with elevated privileges.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Remediation

Install update from vendor's website.