CVE-2018-10518: High severity simple cms vulnerability
In CMS Made Simple (CMSMS) through 2.2.7, the "file delete" operation in the admin dashboard contains an arbitrary file deletion vulnerability that can cause DoS, exploitable by an admin user, because the attacker can remove all lib/ files in all directories.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-10518?
CVE-2018-10518 is considered a high severity vulnerability due to its potential for arbitrary file deletion.
How do I fix CVE-2018-10518?
To fix CVE-2018-10518, upgrade CMS Made Simple to version 2.2.8 or higher, which addresses this vulnerability.
Who is affected by CVE-2018-10518?
All versions of CMS Made Simple up to and including 2.2.7 are affected by CVE-2018-10518.
What kind of attacks are possible with CVE-2018-10518?
CVE-2018-10518 allows an admin user to perform arbitrary file deletion, potentially leading to a denial-of-service condition when critical files are removed.
Can CVE-2018-10518 be exploited remotely?
No, CVE-2018-10518 requires access to the admin dashboard, so it can only be exploited by users with admin privileges.