vendor:
CmsMadeSimple
by:
Mirabbas Agalarov
7.5
CVSS
HIGH
Stored Cross-Site Scripting (XSS)
79
CWE
Product Name: CmsMadeSimple
Affected Version From: v2.2.17
Affected Version To: v2.2.17
Patch Exists: NO
Related CWE:
CPE: a:cmsmadesimple:cmsmadesimple:2.2.17
Platforms Tested: Linux
2023
CmsMadeSimple v2.2.17 – Stored Cross-Site Scripting (XSS)
The CmsMadeSimple v2.2.17 application is vulnerable to stored cross-site scripting (XSS) attacks. An attacker can exploit this vulnerability by injecting malicious code into the metadata section, which will be executed when the content is viewed.
Mitigation:
To mitigate this vulnerability, users should ensure that all user-supplied input is properly sanitized and validated before being displayed on web pages.