High severity7.8NVD Advisory· Published Mar 20, 2020· Updated Jun 17, 2026
CVE-2020-10682
CVE-2020-10682
Description
The Filemanager in CMS Made Simple 2.2.13 allows remote code execution via a .php.jpegd JPEG file, as demonstrated by m1_files[] to admin/moduleinterface.php. The file should be sent as application/octet-stream and contain PHP code (it need not be a valid JPEG file).
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4- cpe:2.3:a:cmsmadesimple:cms_made_simple:2.2.13:*:*:*:*:*:*:*
- CMS Made Simple/CMS Made Simpledescription
- Range: =2.2.13
- Range: =2.2.13
Patches
Vulnerability mechanics
References
1- dev.cmsmadesimple.org/bug/view/12275nvdExploitVendor Advisory
News mentions
0No linked articles in our index yet.