CVE-2025-63678
EUVD-2025-5083010.11.2025, 23:15
An authenticated arbitrary file upload vulnerability in the /uploads/ endpoint of CMS Made Simple Foundation File Manager v2.2.22 allows attackers with Administrator privileges to execute arbitrary code via uploading a crafted PHP file.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| cmsmadesimple | file_manager | 2.2.22 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration