CVE-2022-23906: Malicious File Upload
CMS Made Simple v2.2.15 was discovered to contain a Remote Command Execution (RCE) vulnerability via the upload avatar function. This vulnerability is exploited via a crafted image file.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-23906?
CVE-2022-23906 is a Remote Command Execution (RCE) vulnerability in CMS Made Simple v2.2.15.
How does CVE-2022-23906 impact CMS Made Simple?
CVE-2022-23906 allows an attacker to execute arbitrary commands on a vulnerable CMS Made Simple v2.2.15 installation via the upload avatar function.
What is the severity of CVE-2022-23906?
CVE-2022-23906 has a severity rating of 7.2, which is considered high.
How can I fix CVE-2022-23906 in CMS Made Simple v2.2.15?
To fix CVE-2022-23906, you should update your CMS Made Simple installation to a version that is not affected by the vulnerability.
Where can I find more information about CVE-2022-23906?
You can find more information about CVE-2022-23906 in the official CMS Made Simple bug report: http://dev.cmsmadesimple.org/bug/view/12502