CVE-2017-11405

Publication date

2017-07-18 00:00:00

Family

mitre

State

PUBLISHED

Description

In CMS Made Simple (CMSMS) 2.2.2, remote authenticated administrators can upload a .php file via a CMSContentManager action to admin/moduleinterface.php, followed by a FilePicker action to admin/moduleinterface.php in which type=image is changed to type=file.