TROYANOSYVIRUS
Volver a CVEs

CVE-2024-55085

CRITICAL
9.8

Descripcion

GetSimple CMS CE 3.3.19 suffers from arbitrary code execution in the template editing function in the background management system, which can be used by an attacker to implement RCE.

Detalles CVE

Puntuacion CVSS v3.19.8
SeveridadCRITICAL
Vector CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vector de ataqueNETWORK
ComplejidadLOW
Privilegios requeridosNONE
Interaccion usuarioNONE
Publicado12/16/2024
Ultima modificacion4/17/2025
Fuentenvd
Avistamientos honeypot0

Productos afectados

getsimple-ce:getsimple_cms

Debilidades (CWE)

CWE-94

Correlaciones IOC

Sin correlaciones registradas

This product uses data from the NVD API but is not endorsed or certified by the NVD.