Vulnerability Description
CMS Made Simple 2.2.14 allows an authenticated user with access to the Content Manager to edit content and put persistent XSS payload in the affected text fields. The user can get cookies from every authenticated user who visits the website.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cmsmadesimple | Cms Made Simple | 2.2.14 |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/159434/CMS-Made-Simple-2.2.14-Cross-Site-ScExploitThird Party AdvisoryVDB Entry
- https://www.cmsmadesimple.orgProduct
- https://www.exploit-db.com/exploits/48851ExploitThird Party AdvisoryVDB Entry
- https://www.youtube.com/watch?v=M6D7DmmjLak&t=22sExploitThird Party Advisory
- http://packetstormsecurity.com/files/159434/CMS-Made-Simple-2.2.14-Cross-Site-ScExploitThird Party AdvisoryVDB Entry
- https://www.cmsmadesimple.orgProduct
- https://www.exploit-db.com/exploits/48851ExploitThird Party AdvisoryVDB Entry
- https://www.youtube.com/watch?v=M6D7DmmjLak&t=22sExploitThird Party Advisory
FAQ
What is CVE-2020-24860?
CVE-2020-24860 is a vulnerability with a CVSS score of 5.4 (MEDIUM). CMS Made Simple 2.2.14 allows an authenticated user with access to the Content Manager to edit content and put persistent XSS payload in the affected text fields. The user can get cookies from every a...
How severe is CVE-2020-24860?
CVE-2020-24860 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-24860?
Check the references section above for vendor advisories and patch information. Affected products include: Cmsmadesimple Cms Made Simple.