CVE-2018-9921: Cmsmadesimple CMS Made Simple
Medium severity, CVSS 5.3. EPSS: 1.4% chance of exploitation in the next 30 days.
In CMS Made Simple 2.2.7, a Directory Traversal issue makes it possible to determine the existence of files and directories outside the web-site installation directory, and determine whether a file has contents matching a specified checksum. The attack uses an admin/checksum.php?__c= request.
Affected products
- Cmsmadesimple CMS Made Simple: version 2.2.7 only
Published 2018-04-23. Last modified 2026-06-17.