CVE-2024-27623: Medium severity CMS Made Simple CMS Made Simple vulnerability
Published Mar 5, 2024
·Updated
CMS Made Simple version 2.2.19 is vulnerable to Server-Side Template Injection (SSTI). The vulnerability exists within the Design Manager, particularly when editing the Breadcrumbs.
Affected Software
2 affected components
CMS Made Simple CMS Made Simple
CMSmadesimple CMS Made Simple=2.2.19
Event History
Mar 5, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-27623?
CVE-2024-27623 is classified as a high severity vulnerability due to its potential for remote code execution through Server-Side Template Injection.
2
How do I fix CVE-2024-27623?
Fix CVE-2024-27623 by upgrading to the latest version of CMS Made Simple, specifically a version higher than 2.2.19.
3
What software is affected by CVE-2024-27623?
CVE-2024-27623 affects CMS Made Simple version 2.2.19 and earlier versions.
4
What type of vulnerability is CVE-2024-27623?
CVE-2024-27623 is a Server-Side Template Injection (SSTI) vulnerability.
5
In which component of CMS Made Simple can CVE-2024-27623 be exploited?
CVE-2024-27623 can be exploited within the Design Manager, particularly when editing the Breadcrumbs.