CVE-2023-43352: Code Injection
Published Oct 26, 2023
·Updated
An issue in CMSmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a crafted payload to the Content Manager Menu component.
Affected Software
1 affected component
CMSmadesimple CMS Made Simple=2.2.18
Event History
Oct 26, 2023
CVE Published
12:00 AM
Data Sourced
12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2023-43352?
The severity of CVE-2023-43352 is high with a severity value of 7.8.
2
How does CVE-2023-43352 affect CMS Made Simple?
CVE-2023-43352 allows a local attacker to execute arbitrary code via a crafted payload to the Content Manager Menu component in CMS Made Simple version 2.2.18.
3
How can I fix CVE-2023-43352?
To fix CVE-2023-43352, it is recommended to update CMS Made Simple to a version that is not affected by this vulnerability.
4
Where can I find more information about CVE-2023-43352?
More information about CVE-2023-43352 can be found at the following references: [link1](https://github.com/sromanhu/CMSmadesimple-SSTI--Content), [link2](https://github.com/sromanhu/CVE-2023-43352-CMSmadesimple-SSTI--Content).