CVE-2024-27623

CMS Made Simple version 2.2.19 is vulnerable to Server-Side Template Injection (SSTI). The vulnerability exists within the Design Manager, particularly when editing the Breadcrumbs.
Configurations

Configuration 1 (hide)

cpe:2.3:a:cmsmadesimple:cms_made_simple:2.2.19:*:*:*:*:*:*:*

History

No history.

Information

Published : 2024-03-05 14:15

Updated : 2025-12-17 16:16


NVD link : CVE-2024-27623

Mitre link : CVE-2024-27623

CVE.ORG link : CVE-2024-27623


JSON object : View

Products Affected

cmsmadesimple

  • cms_made_simple
CWE
CWE-1336

Improper Neutralization of Special Elements Used in a Template Engine