CMSimple 5.24 ships with CSRF protection disabled by default, which turns csrfProtection() into a no-op on every state-changing admin request, and it does not send the csrf_token hidden field in admin forms. Because administrator authentication is cookie-only and no CSRF token is enforced, an unauthenticated attacker can induce a logged-in administrator's browser to issue a forged content-save request with a text payload containing a scripting marker. The marker is stored verbatim into content/content.php; on every subsequent page view evaluate_cmsimple_scripting() (functions.php) executes the marker body with PHP eval() — for all visitors, including unauthenticated ones. This yields persistent remote code execution on the web server.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://github.com/15536818056/CVE/issues/5 |
|
History
Tue, 22 Sep 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | CMSimple 5.24 Persistent Remote Code Execution from Disabled CSRF Protection | |
| Weaknesses | CWE-352 CWE-94 |
Tue, 22 Sep 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Cmsimple
Cmsimple cmsimple |
|
| Vendors & Products |
Cmsimple
Cmsimple cmsimple |
Tue, 22 Sep 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | CMSimple 5.24 ships with CSRF protection disabled by default, which turns csrfProtection() into a no-op on every state-changing admin request, and it does not send the csrf_token hidden field in admin forms. Because administrator authentication is cookie-only and no CSRF token is enforced, an unauthenticated attacker can induce a logged-in administrator's browser to issue a forged content-save request with a text payload containing a scripting marker. The marker is stored verbatim into content/content.php; on every subsequent page view evaluate_cmsimple_scripting() (functions.php) executes the marker body with PHP eval() — for all visitors, including unauthenticated ones. This yields persistent remote code execution on the web server. | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-09-22T19:29:21.204Z
Reserved: 2026-09-10T00:00:00.000Z
Link: CVE-2026-88418
No data.
Status : Received
Published: 2026-09-22T20:17:10.960
Modified: 2026-09-22T20:17:10.960
Link: CVE-2026-88418
No data.
OpenCVE Enrichment
Updated: 2026-09-22T21:00:16Z
Weaknesses
No weakness.