Beveiligingsadvies

CVE-2017-11405

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2017-07-18 00:00:00
Laatst bijgewerkt 2024-09-16 23:00:22
Toegewezen door mitre
CVSS-score geen score
Status PUBLISHED

Beschrijving

In CMS Made Simple (CMSMS) 2.2.2, remote authenticated administrators can upload a .php file via a CMSContentManager action to admin/moduleinterface.php, followed by a FilePicker action to admin/moduleinterface.php in which type=image is changed to type=file.