CVE-2024-27622

A remote code execution vulnerability has been identified in the User Defined Tags module of CMS Made Simple version 2.2.19 / 2.2.21. This vulnerability arises from inadequate sanitization of user-supplied input in the 'Code' section of the module. As a result, authenticated users with administrative privileges can inject and execute arbitrary PHP code.
Configurations

No configuration.

History

05 Aug 2024, 21:35

Type Values Removed Values Added
CWE CWE-75
CWE-94
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.2

21 Jun 2024, 22:15

Type Values Removed Values Added
Summary (en) A remote code execution vulnerability has been identified in the User Defined Tags module of CMS Made Simple version 2.2.19. This vulnerability arises from inadequate sanitization of user-supplied input in the 'Code' section of the module. As a result, authenticated users with administrative privileges can inject and execute arbitrary PHP code. (en) A remote code execution vulnerability has been identified in the User Defined Tags module of CMS Made Simple version 2.2.19 / 2.2.21. This vulnerability arises from inadequate sanitization of user-supplied input in the 'Code' section of the module. As a result, authenticated users with administrative privileges can inject and execute arbitrary PHP code.

07 Jun 2024, 16:15

Type Values Removed Values Added
References
  • () https://packetstormsecurity.com/files/177241/CMS-Made-Simple-2.2.19-Remote-Code-Execution.html -
Summary
  • (es) Se ha identificado una vulnerabilidad de ejecución remota de código en el módulo Etiquetas definidas por el usuario de CMS Made Simple versión 2.2.19. Esta vulnerabilidad surge de una sanitización inadecuada de la entrada proporcionada por el usuario en la sección "Código" del módulo. Como resultado, los usuarios autenticados con privilegios administrativos pueden inyectar y ejecutar código PHP arbitrario.

05 Mar 2024, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-03-05 14:15

Updated : 2024-08-05 21:35


NVD link : CVE-2024-27622

Mitre link : CVE-2024-27622

CVE.ORG link : CVE-2024-27622


JSON object : View

Products Affected

No product.

CWE
CWE-75

Failure to Sanitize Special Elements into a Different Plane (Special Element Injection)

CWE-94

Improper Control of Generation of Code ('Code Injection')