CVE-2018-1000094
HIGHCMS Made Simple <2.2.5 - Authenticated RCE
Title source: llmDescription
CMS Made Simple version 2.2.5 contains a Remote Code Execution vulnerability in File Manager that can result in Allows an authenticated admin that has access to the file manager to execute code on the server. This attack appear to be exploitable via File upload -> copy to any extension.
Exploits (4)
exploitdb
WORKING POC
VERIFIED
by Mustafa Hasan · pythonwebappsphp
https://www.exploit-db.com/exploits/44976
metasploit
WORKING POC
EXCELLENT
by Mustafa Hasen, Jacob Robles · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/http/cmsms_upload_rename_rce.rb
Scores
CVSS v3
7.2
EPSS
0.5492
EPSS Percentile
98.1%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-434
Status
published
Products (1)
cmsmadesimple/cms_made_simple
2.2.5
Published
Mar 13, 2018
Tracked Since
Feb 18, 2026