← back
CVE-2017-8912

CVE-2017-8912

CVSS 7.2 HIGHEPSS 3.1%CWE-94
Vexday Risk Score
41Attention
SSVC decision (CISA)
Attend
PoC available → attend closely
CVSS 7.2EPSS 3.1%KEV nãoPoC públicaNuclei Metasploit Patch
Lifecycle
10 May 2017Public PoC
12 May 2017Published on NVD
Recommendation: Plan a near-term fix — a public PoC already exists.
CMS Made Simple (CMSMS) 2.1.6 allows remote authenticated administrators to execute arbitrary PHP code via the code parameter to admin/editusertag.php, related to the CreateTagFunction and CallUserTag functions. NOTE: the vendor reportedly has stated this is "a feature, not a bug.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →