Description
CMSimple 5.4 contains an authenticated remote code execution vulnerability that allows logged-in attackers to inject malicious PHP code into template files. Attackers can exploit the template editing functionality by crafting a reverse shell payload and saving it through the template editing endpoint with a valid CSRF token.
Problem types
Improper Control of Generation of Code ('Code Injection')
Product status
Credits
pussycat0x
References
www.exploit-db.com/exploits/50356 (ExploitDB-50356)
www.cmsimple.org/ (Official CMSimple Homepage)
www.vulncheck.com/...ote-code-execution-via-template-editing (VulnCheck Advisory: CMSimple 5.4 Authenticated Remote Code Execution via Template Editing)
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.