vendor:
CMS Made Simple
by:
bt0
5.4
CVSS
MEDIUM
Cross-Site Scripting (XSS)
79
CWE
Product Name: CMS Made Simple
Affected Version From: 2.2.15
Affected Version To: 2.2.15
Patch Exists: YES
Related CWE: CVE-2021-28935
CPE: a:cms_made_simple:cms_made_simple:2.2.15
Metasploit:
https://www.rapid7.com/db/vulnerabilities/alma_linux-cve-2020-28935/, https://www.rapid7.com/db/vulnerabilities/amazon-linux-ami-2-cve-2020-28935/, https://www.rapid7.com/db/vulnerabilities/oracle_linux-cve-2020-28935/, https://www.rapid7.com/db/vulnerabilities/centos_linux-cve-2020-28935/
Platforms Tested:
2021
CMS Made Simple 2.2.15 – ‘title’ Cross-Site Scripting (XSS)
If you log into Admin panel and open My Preferences you could be able to exploit XSS in title field. Reflected XSS in /admin/addbookmark.php.
Mitigation:
To mitigate this vulnerability, it is recommended to sanitize user input and validate it before displaying it on the web application.