CVE-2017-1000453: Critical severity CMSmadesimple CMS Made Simple vulnerability
Published Jan 2, 2018
·Updated
CMS Made Simple version 2.1.6 and 2.2 are vulnerable to Smarty templating injection in some core modules, resulting in unauthenticated PHP code execution.
Affected Software
2 affected components
CMSmadesimple CMS Made Simple<2.2
CMSmadesimple CMS Made Simple>=2.2.1
Event History
Jan 2, 2018
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-1000453?
CVE-2017-1000453 has a high severity due to the potential for unauthenticated PHP code execution.
2
How do I fix CVE-2017-1000453?
To fix CVE-2017-1000453, update CMS Made Simple to version 2.2.1 or later.
3
Which versions of CMS Made Simple are affected by CVE-2017-1000453?
CMS Made Simple versions 2.1.6 and 2.2 are affected by CVE-2017-1000453.
4
What vulnerability does CVE-2017-1000453 represent?
CVE-2017-1000453 represents a vulnerability involving Smarty templating injection in core modules.
5
Can CVE-2017-1000453 be exploited remotely?
Yes, CVE-2017-1000453 can be exploited remotely without authentication.