Vulnerability record · CVE-2023-36969 · published 6 July 2023
CVE-2023-36969: CMS Made Simple file upload flaw enables remote command execution
Cmsmadesimple · Cms Made Simple
CMS Made Simple v2.2.17 allows an authenticated user to upload files without adequate restriction, leading to remote command execution. The flaw is an unrestricted file upload (CWE-434) that lets an attacker place executable content on the server. It matters because successful exploitation gives full control of the web application host.
Description
CMS Made Simple v2.2.17 is vulnerable to Remote Command Execution via the File Upload Function.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityHigh CVSS (8.8) and very high EPSS with public exploit references make this a likely target, though it requires authentication and is not in KEV.
What it is
CMS Made Simple v2.2.17 allows an authenticated user to upload files without adequate restriction, leading to remote command execution. The flaw is an unrestricted file upload (CWE-434) that lets an attacker place executable content on the server. It matters because successful exploitation gives full control of the web application host.
Impact
An attacker gains remote command execution on the server, with high impact to confidentiality, integrity and availability. This can lead to full compromise of the CMS instance and any data or services it can reach.
Attack surface
The flaw is reached over the network through the file upload function, requiring low privileges (an authenticated account) and no user interaction. The CVSS vector is AV:N/AC:L/PR:L/UI:N, so any valid low-privileged user is enough.
Exploitation
Public exploit references are tagged Exploit, and EPSS is 0.49317 (98.8th percentile), indicating a high likelihood of exploitation activity. The CVE is not listed in CISA KEV, so no confirmed in-the-wild exploitation is recorded there.
What to do
- Upgrade CMS Made Simple to a version later than 2.2.17 that fixes the file upload handling.
- Restrict upload permissions to trusted roles and remove unused accounts.
- Enforce server-side file type and extension validation, and store uploads outside the web root.
- Disable execution of scripts in upload directories via web server configuration.
- Monitor and alert on unexpected executable files appearing in upload or content directories.
Detection
- Review web server logs for POST requests to upload endpoints followed by requests to newly written files.
- Alert on creation of executable files (php, phtml, etc.) in upload or media directories.
- Monitor for unusual child processes spawned by the web server user.
- Audit CMS user accounts for unexpected or recently created low-privileged users.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2023-36969 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-36969), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.