Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://github.com/15536818056/CVE/issues/5 |
|
Tue, 22 Sep 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | CMSimple 5.24 Persistent Remote Code Execution from Disabled CSRF Protection | |
| Weaknesses | CWE-352 CWE-94 |
Tue, 22 Sep 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Cmsimple
Cmsimple cmsimple |
|
| Vendors & Products |
Cmsimple
Cmsimple cmsimple |
Tue, 22 Sep 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | CMSimple 5.24 ships with CSRF protection disabled by default, which turns csrfProtection() into a no-op on every state-changing admin request, and it does not send the csrf_token hidden field in admin forms. Because administrator authentication is cookie-only and no CSRF token is enforced, an unauthenticated attacker can induce a logged-in administrator's browser to issue a forged content-save request with a text payload containing a scripting marker. The marker is stored verbatim into content/content.php; on every subsequent page view evaluate_cmsimple_scripting() (functions.php) executes the marker body with PHP eval() — for all visitors, including unauthenticated ones. This yields persistent remote code execution on the web server. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-09-22T19:29:21.204Z
Reserved: 2026-09-10T00:00:00.000Z
Link: CVE-2026-88418
No data.
Status : Received
Published: 2026-09-22T20:17:10.960
Modified: 2026-09-22T20:17:10.960
Link: CVE-2026-88418
No data.
OpenCVE Enrichment
Updated: 2026-09-22T21:00:16Z