CVE-2020-17462: Malicious File Upload
Published Aug 14, 2020
·Updated
CMS Made Simple 2.2.14 allows Authenticated Arbitrary File Upload because the File Manager does not block .ptar files, a related issue to CVE-2017-16798.
Affected Software
1 affected component
CMSmadesimple CMS Made Simple=2.2.14
Event History
Aug 14, 2020
CVE Published
via MITRE·02:10 PM
Data Sourced
via MITRE·02:10 PM
Description
Frequently Asked Questions
1
What is CVE-2020-17462?
CVE-2020-17462 is a vulnerability in CMS Made Simple 2.2.14 that allows authenticated arbitrary file upload due to a lack of file blocking for .ptar files.
2
How severe is CVE-2020-17462?
CVE-2020-17462 has a severity score of 7.8, which is classified as high.
3
How does CVE-2020-17462 affect CMS Made Simple?
CVE-2020-17462 affects CMS Made Simple 2.2.14.
4
What is the Common Weakness Enumeration (CWE) associated with CVE-2020-17462?
CVE-2020-17462 is associated with CWE-434, which is the Weaknesses in Enforced Constraints.
5
Is there a known exploit for CVE-2020-17462?
Yes, there is a known exploit for CVE-2020-17462. You can find more information about it in the reference provided.