CVE-2017-11404: Malicious File Upload
Published Jul 18, 2017
·Updated
In CMS Made Simple (CMSMS) 2.2.2, remote authenticated administrators can upload a .php file via a FileManager action to admin/moduleinterface.php.
Affected Software
1 affected component
CMSmadesimple CMS Made Simple=2.2.2
Event History
Jul 18, 2017
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-11404?
CVE-2017-11404 has a medium severity rating due to its potential for unauthorized remote code execution by authenticated users.
2
How do I fix CVE-2017-11404?
To fix CVE-2017-11404, upgrade CMS Made Simple to a version later than 2.2.2 where the vulnerability has been patched.
3
Who is affected by CVE-2017-11404?
CVE-2017-11404 affects remote authenticated administrators using CMS Made Simple version 2.2.2.
4
What types of files can be uploaded due to CVE-2017-11404?
CVE-2017-11404 allows remote authenticated administrators to upload .php files, which pose a risk of remote code execution.
5
Is CVE-2017-11404 still a threat?
CVE-2017-11404 is a threat if vulnerable systems running CMS Made Simple 2.2.2 have not been updated to a secure version.