CVE-2024-58280: CMSimple 5.15 Remote Command Execution via Extensions Configuration
CMSimple 5.15 contains a remote command execution vulnerability that allows authenticated attackers to modify file extensions and upload malicious PHP files. Attackers can append ',php' to Extensionsuserfiles and upload a shell script to the media directory to execute arbitrary code on the server.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-58280?
CVE-2024-58280 is considered a critical vulnerability due to its potential for remote command execution by authenticated attackers.
How do I fix CVE-2024-58280?
To fix CVE-2024-58280, ensure that CMSimple is updated to the latest version that addresses this vulnerability, removing the ability to modify file extensions.
Who is affected by CVE-2024-58280?
CVE-2024-58280 affects users of CMSimple version 5.15 that allow authenticated access.
What types of attacks are possible with CVE-2024-58280?
CVE-2024-58280 allows attackers to exploit the vulnerability to upload and execute malicious PHP files on the server.
Is user authentication sufficient to protect against CVE-2024-58280?
No, user authentication is not sufficient alone as CVE-2024-58280 allows authenticated attackers to execute remote commands.