Remote Command Execution Vulnerability in CMS Made Simple
CVE-2022-23906
7.2HIGH
What is CVE-2022-23906?
CMS Made Simple version 2.2.15 is vulnerable to a Remote Command Execution (RCE) vulnerability through the avatar upload function. This security flaw can be exploited by uploading a specially crafted image file, allowing unauthorized command execution on the server.
