CVE-2019-9692

MEDIUM

CMS Made Simple < 2.2.10 - Unrestricted File Upload via Watermark Image Extension Bypass

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 3 public exploits for CVE-2019-9692. PoCs published by Metasploit, Daniele Scanu, Daniele Scanu, Fabio Cogno, including Metasploit module exploits/multi/http/cmsms_showtime2_rce.

AI-analyzed exploit summary This Metasploit module exploits a file upload vulnerability in CMS Made Simple's Showtime2 module (CVE-2019-9692), allowing authenticated users to upload malicious PHP files disguised as watermark images, leading to remote code execution.

Description

class.showtime2_image.php in CMS Made Simple (CMSMS) before 2.2.10 does not ensure that a watermark file has a standard image file extension (GIF, JPG, JPEG, or PNG).

Exploits (3)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotephp
https://www.exploit-db.com/exploits/46627

This Metasploit module exploits a file upload vulnerability in CMS Made Simple's Showtime2 module (CVE-2019-9692), allowing authenticated users to upload malicious PHP files disguised as watermark images, leading to remote code execution.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: CMS Made Simple (CMSMS) Showtime2 module <= 3.6.2
Auth required
Prerequisites: Authenticated user with 'Use Showtime2' privilege · Showtime2 module installed and vulnerable version
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by Daniele Scanu · pythonwebappsphp
https://www.exploit-db.com/exploits/46546

This exploit targets an authenticated arbitrary file upload vulnerability in the Showtime2 module for CMS Made Simple. It logs in, uploads a PHP shell, and spawns a reverse shell using netcat.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: CMS Made Simple with Showtime2 module <= 3.6.2
Auth required
Prerequisites: Valid admin credentials · Showtime2 module installed and vulnerable
devstral-2 · analyzed Feb 16, 2026 Full analysis →
metasploit WORKING POC NORMAL
by Daniele Scanu, Fabio Cogno · rubypocphp
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/http/cmsms_showtime2_rce.rb

This Metasploit module exploits a file upload vulnerability in CMS Made Simple's Showtime2 module (CVE-2019-9692), allowing authenticated users to upload malicious PHP files and achieve remote code execution.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: CMS Made Simple (CMSMS) Showtime2 module <= 3.6.2
Auth required
Prerequisites: Authenticated user with 'Use Showtime2' privilege · Showtime2 module installed and vulnerable
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (6)

Core 6
Core References
Exploit, Third Party Advisory, VDB Entry exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/46546/
Exploit, Third Party Advisory, VDB Entry exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/46627/

Scores

CVSS v3 6.5
EPSS 0.5929
EPSS Percentile 98.3%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

Details

CWE
CWE-434
Status published
Products (1)
cmsmadesimple/cms_made_simple < 2.2.10
Published Mar 11, 2019
Tracked Since Feb 18, 2026