Executive brief
CMS Made Simple, a popular content management system, contains a security flaw in its UserGuide module. An attacker with administrative privileges can exploit this to access or manipulate files outside of the intended directory. This could lead to the exposure of sensitive system information or unauthorized changes to website files.
Technical details
A path traversal vulnerability (CWE-22) exists in CMS Made Simple up to version 2.2.22. The flaw is located within the _copyFilesToFolder function in the modules/UserGuide/lib/class.UserGuideImporterExporter.php library of the UserGuide Module XML Import component. A remote attacker with high privileges (PR:H) can manipulate file paths during the XML import process to read or write files outside of the intended directory. While a proof-of-concept exploit is publicly available, the vendor has stated that a fix is planned for the next release.
Affected products
- CMS Made Simple CMS Made Simple up to 2.2.22
Timeline
- 2026-03-31: disclosed: Vulnerability reported and public exploit released.
- 2026-03-31: advisory: NVD published CVE-2026-5203.