Description CMS Made Simple 2.2.1 Local File Inclusion Remediation Update to CMS Made Simple 2.2.2 or later. References http://www.cmsmadesimple.org/2017/07/Announcing-CMSMS-2.2.2-Hearts-Content Related Vulnerabilities TYPO3 Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2022-23503) PHP allow_url_fopen Is Enabled WordPress Plugin Media Library Assistant Multiple Vulnerabilities (2.81) XWiki Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2023-29214) XWikiplatform Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2024-37899) Severity Medium Classification CWE-94 CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N Tags File Inclusion