216.73.216.6

CVE-2024-58280

· Published 10/12/2025 22:16 · Modified 12/12/2025 15:18

Labels: CVE-2024-58280 2025-12-10CVE-2024-58280CWE-403[email protected]

Essential information

Published
10/12/2025 22:16
Modified
12/12/2025 15:18
Author
Creator
CVSS
8.6 HIGH (v3) 8.6 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

CMSimple 5.15 contains a remote command execution vulnerability that allows authenticated attackers to modify file extensions and upload malicious PHP files. Attackers can append ',php' to Extensions_userfiles and upload a shell script to the media directory to execute arbitrary code on the server.

NVD status

Status
Undergoing Analysis — CVE is currently being analyzed by NVD staff, this process results in association of reference link tags, CVSS scores, CWE association, and CPE applicability statements.
Source
[email protected]
NVD
View on NVD

References