CVE-2018-10517
HIGHCMS Made Simple < 2.2.7 - Authenticated Remote Code Execution via Module Import XML Package
Title source: manualExploitation Summary
EIP tracks 2 public exploits for CVE-2018-10517. PoCs published by Lucian Ioan Nitescu, 0x00-0x00.
AI-analyzed exploit summary This exploit targets CMS Made Simple 2.2.7 by uploading a malicious plugin via the admin interface, achieving remote code execution. It leverages a file upload vulnerability to deploy a backdoor disguised as a Matomo plugin.
Description
In CMS Made Simple (CMSMS) through 2.2.7, the "module import" operation in the admin dashboard contains a remote code execution vulnerability, exploitable by an admin user, because an XML Package can contain base64-encoded PHP code in a data element.
Exploits (2)
This exploit targets CMS Made Simple 2.2.7 by uploading a malicious plugin via the admin interface, achieving remote code execution. It leverages a file upload vulnerability to deploy a backdoor disguised as a Matomo plugin.
This PowerShell script exploits CVE-2018-10517, an authenticated RCE vulnerability in CMS Made Simple 2.2.7, by uploading a malicious module that drops a PHP file for command execution. The exploit leverages a multipart form upload to bypass restrictions and execute arbitrary commands.
References (2)
Scores
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H