First published: Fri Apr 27 2018(Updated: )
In CMS Made Simple (CMSMS) through 2.2.7, the "file delete" operation in the admin dashboard contains an arbitrary file deletion vulnerability that can cause DoS, exploitable by an admin user, because the attacker can remove all lib/ files in all directories.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Simple CMS | <=2.2.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-10518 is considered a high severity vulnerability due to its potential for arbitrary file deletion.
To fix CVE-2018-10518, upgrade CMS Made Simple to version 2.2.8 or higher, which addresses this vulnerability.
All versions of CMS Made Simple up to and including 2.2.7 are affected by CVE-2018-10518.
CVE-2018-10518 allows an admin user to perform arbitrary file deletion, potentially leading to a denial-of-service condition when critical files are removed.
No, CVE-2018-10518 requires access to the admin dashboard, so it can only be exploited by users with admin privileges.