CVE-2021-43741

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
13/04/2022
Last modified:
20/04/2022

Description

CMSimple 5.4 is vulnerable to Directory Traversal. The vulnerability exists when a user changes the file name to malicious file on config.php leading to remote code execution.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:cmsimple:cmsimple:5.4:*:*:*:*:*:*:*