First published: Tue Jan 02 2018(Updated: )
CMS Made Simple version 2.1.6 and 2.2 are vulnerable to Smarty templating injection in some core modules, resulting in unauthenticated PHP code execution.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
CMS Made Simple | <2.2 | |
CMS Made Simple | >=2.2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-1000453 has a high severity due to the potential for unauthenticated PHP code execution.
To fix CVE-2017-1000453, update CMS Made Simple to version 2.2.1 or later.
CMS Made Simple versions 2.1.6 and 2.2 are affected by CVE-2017-1000453.
CVE-2017-1000453 represents a vulnerability involving Smarty templating injection in core modules.
Yes, CVE-2017-1000453 can be exploited remotely without authentication.