CVE-2022-41544: Code Injection
Published Oct 18, 2022
·Updated
GetSimple CMS v3.3.16 was discovered to contain a remote code execution (RCE) vulnerability via the editedfile parameter in admin/theme-edit.php.
Affected Software
1 affected component
Get-simple Getsimple Cms=3.3.16
Event History
Oct 18, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2022-41544.
2
What is the severity level of CVE-2022-41544?
The severity level of CVE-2022-41544 is critical.
3
How does CVE-2022-41544 affect GetSimple CMS?
CVE-2022-41544 affects GetSimple CMS version 3.3.16.
4
What is the exploit method of CVE-2022-41544?
CVE-2022-41544 exploits the edited_file parameter in admin/theme-edit.php to execute remote code.
5
Are there any known fixes for CVE-2022-41544?
At the moment, there are no known fixes for CVE-2022-41544. It is recommended to update to a non-vulnerable version or apply any available patches provided by the vendor.