vendor:
GetSimple CMS
by:
Roel van Beurden
5.5
CVSS
MEDIUM
Persistent Cross-Site Scripting
79
CWE
Product Name: GetSimple CMS
Affected Version From: 3.3.16
Affected Version To: 3.3.16
Patch Exists: NO
Related CWE:
CPE: a:getsimple:getsimple:3.3.16
Platforms Tested: Linux
2020
GetSimple CMS 3.3.16 – Persistent Cross-Site Scripting (Authenticated)
GetSimple CMS 3.3.16 allows in parameter 'permalink' on the Settings page persistent Cross Site Scripting which is executed when you create and open a new page.
Mitigation:
Sanitize and validate user input to prevent script execution.