Description
CMS Made Simple (CMSMS) through 2.2.7 contains an arbitrary code execution vulnerability in the admin dashboard because the implementation uses "eval('function testfunction'.rand()" and it is possible to bypass certain restrictions on these "testfunction" functions.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2018-2168 | CMS Made Simple (CMSMS) through 2.2.7 contains an arbitrary code execution vulnerability in the admin dashboard because the implementation uses "eval('function testfunction'.rand()" and it is possible to bypass certain restrictions on these "testfunction" functions. |
References
| Link | Providers |
|---|---|
| https://github.com/itodaro/cve/blob/master/README.md |
|
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-09-16T19:05:45.060Z
Reserved: 2018-04-13T00:00:00.000Z
Link: CVE-2018-10086
No data.
Status : Modified
Published: 2018-04-13T05:29:00.510
Modified: 2024-11-21T03:40:47.733
Link: CVE-2018-10086
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD