CyberRota Analysis
AI-GeneratedA code execution vulnerability in the CoAuthors plugin of CMSimple 5.22 allows authenticated low-privileged users to execute arbitrary server-side code by manipulating the content import feature with crafted external or uploaded text. This could lead to unauthorized access or control over the server, making it critical for organizations using this CMS version to prioritize patching. Users with the ability to modify page content should be particularly vigilant in securing their installations.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
A code execution vulnerability exists in CMSimple 5.22 in the CoAuthors plugin. An authenticated low-privileged user who can modify page content and provide controlled imported content can trigger server-side execution by referencing crafted external or uploaded text content through the affected content import feature.