First published: Fri Aug 14 2020(Updated: )
CMS Made Simple 2.2.14 allows Authenticated Arbitrary File Upload because the File Manager does not block .ptar files, a related issue to CVE-2017-16798.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cmsmadesimple Cms Made Simple | =2.2.14 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-17462 is a vulnerability in CMS Made Simple 2.2.14 that allows authenticated arbitrary file upload due to a lack of file blocking for .ptar files.
CVE-2020-17462 has a severity score of 7.8, which is classified as high.
CVE-2020-17462 affects CMS Made Simple 2.2.14.
CVE-2020-17462 is associated with CWE-434, which is the Weaknesses in Enforced Constraints.
Yes, there is a known exploit for CVE-2020-17462. You can find more information about it in the reference provided.