CVE-2017-16783

CRITICAL

CMS Made Simple <2.1.6 - SSRF

Title source: llm

Description

In CMS Made Simple 2.1.6, there is Server-Side Template Injection via the cntnt01detailtemplate parameter.

Exploits (1)

exploitdb WORKING POC
by Gurkirat Singh · pythonwebappsphp
https://www.exploit-db.com/exploits/48944

Scores

CVSS v3 9.8
EPSS 0.0987
EPSS Percentile 93.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-94
Status published
Products (1)
cmsmadesimple/cms_made_simple 2.1.6
Published Nov 10, 2017
Tracked Since Feb 18, 2026