A remote code execution vulnerability has been identified in the User Defined Tags module of CMS Made Simple version 2.2.19 / 2.2.21. This vulnerability arises from inadequate sanitization of user-supplied input in the 'Code' section of the module. As a result, authenticated users with administrative privileges can inject and execute arbitrary PHP code.
References
Configurations
No configuration.
History
05 Aug 2024, 21:35
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-75 CWE-94 |
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.2 |
21 Jun 2024, 22:15
Type | Values Removed | Values Added |
---|---|---|
Summary | (en) A remote code execution vulnerability has been identified in the User Defined Tags module of CMS Made Simple version 2.2.19 / 2.2.21. This vulnerability arises from inadequate sanitization of user-supplied input in the 'Code' section of the module. As a result, authenticated users with administrative privileges can inject and execute arbitrary PHP code. |
07 Jun 2024, 16:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
|
Summary |
|
05 Mar 2024, 14:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-03-05 14:15
Updated : 2024-08-05 21:35
NVD link : CVE-2024-27622
Mitre link : CVE-2024-27622
CVE.ORG link : CVE-2024-27622
JSON object : View
Products Affected
No product.