SB2018021702 - Remote code execution in CMS Made Simple
Published: February 17, 2018
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Command injection (CVE-ID: CVE-2018-1000094)
The vulnerability allows a remote administrative attacker to execute arbitrary commands on the target system.
The vulnerability exists in the File Manager interface of CMS Made Simple due to insufficient validation of user-supplied input. A remote attacker can upload a malicious file, inject arbitrary commands and execute arbitrary code with elevated privileges.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Remediation
Install update from vendor's website.