← Vulnerability feed

Vulnerability record · CVE-2024-57548 · published 27 January 2025

CVE-2024-57548: Cmsimple incorrect default permissions vulnerability

Cmsimple · Cmsimple

CMSimple 5.16 allows the user to edit log.php file via print page.

9.1 CVSS 3.1 Critical EPSS 0.47% · top 62.0% CWE-276 · Incorrect default permissions
9.1CVSS 3.1 base score
0.47%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 1 tagged exploit
17 Jun 2026Last modified by NVD

Description

CMSimple 5.16 allows the user to edit log.php file via print page.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-57548 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-43741Cmsimple path traversal vulnerabilityCMSimple 5.4 is vulnerable to Directory Traversal. The vulnerability exists when a user changes the file name to malicious file on config.php leading…EPSS 4.7%8.6CVE-2021-47734Cmsimple php remote file inclusion vulnerabilityCMSimple 5.4 contains an authenticated local file inclusion vulnerability that allows remote attackers to manipulate PHP session files and execute ar…EPSS 0.78%8.6CVE-2021-47735Cmsimple code injection vulnerabilityCMSimple 5.4 contains an authenticated remote code execution vulnerability that allows logged-in attackers to inject malicious PHP code into template…EPSS 0.88%8.6CVE-2024-58280Cmsimple vulnerabilityCMSimple 5.15 contains a remote command execution vulnerability that allows authenticated attackers to modify file extensions and upload malicious PH…EPSS 0.94%7.5CVE-2024-57547Cmsimple incorrect permission assignment vulnerabilityInsecure Permissions vulnerability in CMSimple v.5.16 allows a remote attacker to obtain sensitive information via a crafted script to the Functional…EPSS 0.57%7.5CVE-2024-57549Cmsimple path traversal vulnerabilityCMSimple 5.16 allows the user to read cms source code through manipulation of the file name in the file parameter of a GET request.EPSS 0.66%7.5CVE-2024-57546Cmsimple vulnerabilityAn issue in CMSimple v.5.16 allows a remote attacker to obtain sensitive information via a crafted script to the validate link function.EPSS 0.58%7.4CVE-2024-33423Cmsimple vulnerabilityCross-Site Scripting (XSS) vulnerability in the Settings menu of CMSimple v5.15 allows attackers to execute arbitrary web scripts or HTML via a craft…EPSS 0.56%

Source: NIST National Vulnerability Database (record CVE-2024-57548), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.