VYPR
High severity8.8NVD Advisory· Published Dec 10, 2025· Updated Jun 17, 2026

CVE-2024-58280

CVE-2024-58280

Description

CMSimple 5.15 contains a remote command execution vulnerability that allows authenticated attackers to modify file extensions and upload malicious PHP files. Attackers can append ',php' to Extensions_userfiles and upload a shell script to the media directory to execute arbitrary code on the server.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Cmsimple/Cmsimple3 versions
    cpe:2.3:a:cmsimple:cmsimple:5.15:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:cmsimple:cmsimple:5.15:*:*:*:*:*:*:*
    • (no CPE)range: =5.15
    • (no CPE)range: 5.15

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.