Impact
A code execution vulnerability exists in the CoAuthors plugin for CMSimple 5.22. An authenticated low‑privileged user who can modify page content and supply controlled imported content can trigger server‑side execution by referencing crafted external or uploaded text files via the vulnerable content import function. The attacker can run arbitrary code on the web server with the permissions of the web‑application process, potentially compromising the entire site and any associated infrastructure.
Affected Systems
All installations of CMSimple 5.22 that have the CoAuthors plugin enabled are affected. The vulnerability is tied to the import feature of that plugin and is not limited to a specific vendor beyond CMSimple; any configuration that allows authenticated users to upload or reference external text content for import exposes the system.
Risk and Exploitability
The exploit requires authentication with low privileges sufficient to edit pages and invoke the import function. The CVSS score of 8.8 indicates high severity, and the EPSS score is less than 1%, suggesting a low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog, but because it allows arbitrary code execution, the potential impact is high if an attacker gains an authenticated session. The likely attack vector involves an insider or a compromised low‑privileged user providing specially crafted content via the import interface.
OpenCVE Enrichment