CMS Made Simple editusertag.php Remote OS Command Injection Exploit

CMS Made Simple (CMSMS) 2.1.6 allows remote authenticated administrators to execute arbitrary PHP code via the code parameter to admin/editusertag.php, related to the CreateTagFunction and CallUserTag functions.
Exploit Type - Old
Exploits/Remote
Exploit Platform
Exploit Type
Product Name