CVE-2021-28998: Malicious File Upload
File upload vulnerability in CMS Made Simple through 2.2.15 allows remote authenticated attackers to gain a webshell via a crafted phar file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-28998?
The severity of CVE-2021-28998 is high with a CVSS score of 7.2.
How does CVE-2021-28998 allow attackers to gain a webshell?
CVE-2021-28998 allows remote authenticated attackers to gain a webshell by exploiting a file upload vulnerability and uploading a crafted phar file.
Which versions of CMS Made Simple are affected by CVE-2021-28998?
Versions up to and including 2.2.15 of CMS Made Simple are affected by CVE-2021-28998.
Is authentication required for exploiting CVE-2021-28998?
Yes, remote attackers need to be authenticated to exploit CVE-2021-28998.
Are there any references available for CVE-2021-28998?
Yes, you can find references for CVE-2021-28998 at the following links: [reference 1](https://github.com/beerpwn/CVE/blob/master/cms_made_simple_2021/file_upload_RCE/File_upload_to_RCE.md), [reference 2](https://seclists.org/fulldisclosure/2021/Mar/50).