First published: Mon Feb 28 2022(Updated: )
CMS Made Simple v2.2.15 was discovered to contain a Remote Command Execution (RCE) vulnerability via the upload avatar function. This vulnerability is exploited via a crafted image file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cmsmadesimple Cms Made Simple | =2.2.15 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-23906 is a Remote Command Execution (RCE) vulnerability in CMS Made Simple v2.2.15.
CVE-2022-23906 allows an attacker to execute arbitrary commands on a vulnerable CMS Made Simple v2.2.15 installation via the upload avatar function.
CVE-2022-23906 has a severity rating of 7.2, which is considered high.
To fix CVE-2022-23906, you should update your CMS Made Simple installation to a version that is not affected by the vulnerability.
You can find more information about CVE-2022-23906 in the official CMS Made Simple bug report: http://dev.cmsmadesimple.org/bug/view/12502