CVE-2024-55085: Code Injection
Published Dec 16, 2024
·Updated
GetSimple CMS CE 3.3.19 suffers from arbitrary code execution in the template editing function in the background management system, which can be used by an attacker to implement RCE.
Affected Software
2 affected components
GetSimple CMS
Getsimple-ce Getsimple Cms=3.3.19
Event History
Dec 16, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·11:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-55085?
The severity of CVE-2024-55085 is classified as high due to its potential for arbitrary code execution.
2
How do I fix CVE-2024-55085?
To fix CVE-2024-55085, update GetSimple CMS to the latest version where the vulnerability has been addressed.
3
What impact does CVE-2024-55085 have on GetSimple CMS?
CVE-2024-55085 allows an attacker to execute arbitrary code through the template editing function, compromising the security of the CMS.
4
Who is affected by CVE-2024-55085?
Any user or organization utilizing GetSimple CMS CE version 3.3.19 is affected by CVE-2024-55085.
5
Is there a known exploit for CVE-2024-55085?
Yes, CVE-2024-55085 is known to be vulnerable to exploitation by attackers via the template editing feature.