CVE-2017-16783: Code Injection
Published Nov 10, 2017
·Updated
In CMS Made Simple 2.1.6, there is Server-Side Template Injection via the cntnt01detailtemplate parameter.
Affected Software
1 affected component
CMSmadesimple CMS Made Simple=2.1.6
Event History
Nov 10, 2017
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-16783?
CVE-2017-16783 is considered a high-severity vulnerability due to its potential for server-side template injection.
2
How do I fix CVE-2017-16783?
To fix CVE-2017-16783, upgrade your CMS Made Simple installation to a version higher than 2.1.6 that addresses this vulnerability.
3
What are the implications of CVE-2017-16783?
The implications of CVE-2017-16783 include unauthorized code execution, data leakage, and potential full system compromise.
4
Who is affected by CVE-2017-16783?
Users running CMS Made Simple version 2.1.6 are directly affected by CVE-2017-16783.
5
Is CVE-2017-16783 publicly disclosed?
Yes, CVE-2017-16783 is publicly disclosed and documented in various security advisory databases.