CVE-2018-10520: High severity simple cms vulnerability
In CMS Made Simple (CMSMS) through 2.2.7, the "module remove" operation in the admin dashboard contains an arbitrary file deletion vulnerability that can cause DoS, exploitable by an admin user, because the attacker can remove all lib/ files in all directories.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-10520?
CVE-2018-10520 is considered a medium severity vulnerability due to its potential for denial of service attacks.
How do I fix CVE-2018-10520?
To fix CVE-2018-10520, upgrade CMS Made Simple to version 2.2.8 or later.
Who is impacted by CVE-2018-10520?
Any user with admin access to CMS Made Simple versions up to 2.2.7 is vulnerable to CVE-2018-10520.
What kind of attacks can be executed using CVE-2018-10520?
An attacker with admin privileges can exploit CVE-2018-10520 to delete critical library files, leading to a denial of service.
Is there a workaround for CVE-2018-10520?
There is no official workaround for CVE-2018-10520; upgrading to a secure version is recommended.