{"id":"CVE-2026-88418","published":"2026-09-22T20:17:10.960","lastModified":"2026-09-26T00:16:37.843","description":"CMSimple 5.24 ships with CSRF protection disabled by default, which turns csrfProtection() into a no-op on every state-changing admin request, and it does not send the csrf_token hidden field in admin forms. Because administrator authentication is cookie-only and no CSRF token is enforced, an unauthenticated attacker can induce a logged-in administrator's browser to issue a forged content-save request with a text payload containing a scripting marker. The marker is stored verbatim into content/content.php; on every subsequent page view evaluate_cmsimple_scripting() (functions.php) executes the marker body with PHP eval() — for all visitors, including unauthenticated ones. This yields persistent remote code execution on the web server.","cvssScore":8.8,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","cwes":["CWE-352"],"vendors":[],"products":[],"references":[{"url":"https://github.com/15536818056/CVE/issues/5","tags":[]},{"url":"https://github.com/15536818056/CVE/issues/5","tags":[]}],"exploitRefs":[{"url":"https://github.com/15536818056/CVE/issues/5","tags":[]},{"url":"https://github.com/15536818056/CVE/issues/5","tags":[]}],"hasPoc":true,"ai":{"summary":"CMSimple 5.24 lacks CSRF protection, allowing unauthenticated attackers to inject and execute arbitrary PHP code via specially crafted content-save requests.","exploitability":"Exploitation is relatively straightforward as it requires an attacker to induce a logged-in administrator to visit a crafted page. Precondition is that the administrator must be authenticated via a cookie.","blast_radius":"If exploited, this flaw allows persistent remote code execution for all visitors, including unauthenticated ones, potentially leading to full server compromise.","remediation":"Upgrade to CMSimple 5.24.1 or later.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["rce","csrf","web","php"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-28T08:55:28.301Z"}}