First published: Fri May 12 2017(Updated: )
** DISPUTED ** CMS Made Simple (CMSMS) 2.1.6 allows remote authenticated administrators to execute arbitrary PHP code via the code parameter to admin/editusertag.php, related to the CreateTagFunction and CallUserTag functions. NOTE: the vendor reportedly has stated this is "a feature, not a bug."
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Really Simple CMS | =2.1.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-8912 is considered to have a high severity due to the potential for remote code execution by authenticated administrators.
To resolve CVE-2017-8912, it is recommended to upgrade to a later version of CMS Made Simple that addresses this security issue.
CVE-2017-8912 affects users running CMS Made Simple version 2.1.6.
The risks include unauthorized execution of arbitrary PHP code, which can lead to website compromise and data breaches.
The vendor has disputed CVE-2017-8912, claiming that it is a feature rather than a bug.