CVE-2018-10521: Cmsmadesimple CMS Made Simple
Low severity, CVSS 2.7. EPSS: 0.9% chance of exploitation in the next 30 days.
In CMS Made Simple (CMSMS) through 2.2.7, the "file move" operation in the admin dashboard contains an arbitrary file movement vulnerability that can cause DoS, exploitable by an admin user, because config.php can be moved into an incorrect directory.
Affected products
- Cmsmadesimple CMS Made Simple: up to and including 2.2.7
Published 2018-04-27. Last modified 2026-06-17.