First published: Fri Apr 27 2018(Updated: )
In CMS Made Simple (CMSMS) through 2.2.7, the "module remove" operation in the admin dashboard contains an arbitrary file deletion vulnerability that can cause DoS, exploitable by an admin user, because the attacker can remove all lib/ files in all directories.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Simple CMS | <=2.2.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-10520 is considered a medium severity vulnerability due to its potential for denial of service attacks.
To fix CVE-2018-10520, upgrade CMS Made Simple to version 2.2.8 or later.
Any user with admin access to CMS Made Simple versions up to 2.2.7 is vulnerable to CVE-2018-10520.
An attacker with admin privileges can exploit CVE-2018-10520 to delete critical library files, leading to a denial of service.
There is no official workaround for CVE-2018-10520; upgrading to a secure version is recommended.