Description CMS Made Simple 2.2.1 Local File Inclusion Remediation Update to CMS Made Simple 2.2.2 or later. References http://www.cmsmadesimple.org/2017/07/Announcing-CMSMS-2.2.2-Hearts-Content Related Vulnerabilities Webmin v1.920 Unauhenticated Remote Command Execution WordPress Plugin WP Online Store Local File Include and Multiple File Disclosure Vulnerabilities (1.3.1) WordPress Plugin NextGEN Gallery-WordPress Gallery Local File Inclusion (2.1.7) WordPress Plugin TheCartPress eCommerce Shopping Cart 'tcp_class_path' Parameter Remote File Include (1.1.1) Metabase Local File Inclusion (CVE-2021-41277) Severity Medium Classification CWE-94 CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N Tags File Inclusion