CVE-2017-1000454

Severity CVSS v4.0:
Pending analysis
Type:
CWE-74 Injection
Publication date:
02/01/2018
Last modified:
16/01/2018

Description

CMS Made Simple 2.1.6, 2.2, 2.2.1 are vulnerable to Smarty Template Injection in some core components, resulting in local file read before 2.2, and local file inclusion since 2.2.1

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:cmsmadesimple:cms_made_simple:*:*:*:*:*:*:*:* 2.2 (excluding)
cpe:2.3:a:cmsmadesimple:cms_made_simple:*:*:*:*:*:*:*:* 2.2.1 (including)