vendor:
GetSimple CMS
by:
Sureshbabu Narvaneni
6.1
CVSS
MEDIUM
Cross Site Scripting
79
CWE
Product Name: GetSimple CMS
Affected Version From: 3.3.13
Affected Version To: 3.3.13
Patch Exists: YES
Related CWE: CVE-2018-9173
CPE: a:get-simple:get-simple_cms
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Win7 Enterprise x86/Kali Linux 4.12 i686
2018
GetSimple CMS 3.3.13 – Cross Site Scripting Vulnerability
Cross-site scripting (XSS) vulnerability in admin/template/js/uploadify/uploadify.swf in GetSimple CMS 3.3.13 allows remote attackers to inject arbitrary web script or HTML, as demonstrated by the movieName parameter.
Mitigation:
Upgrade to latest release.