CVE-2023-43352
HIGHCMS Made Simple 2.2.18 - Server-Side Template Injection via Content Manager Menu
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2023-43352. PoCs published by sromanhu.
AI-analyzed exploit summary This repository provides a detailed technical analysis of CVE-2023-43352, a Server-Side Template Injection (SSTI) vulnerability in CMS Made Simple v2.2.18. It includes step-by-step exploitation details, payload examples, and screenshots demonstrating the vulnerability's impact, confirming the use of the Smarty template engine.
Description
An issue in CMSmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a crafted payload to the Content Manager Menu component.
Exploits (1)
This repository provides a detailed technical analysis of CVE-2023-43352, a Server-Side Template Injection (SSTI) vulnerability in CMS Made Simple v2.2.18. It includes step-by-step exploitation details, payload examples, and screenshots demonstrating the vulnerability's impact, confirming the use of the Smarty template engine.
References (2)
Scores
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H