Vulnerability Description
A cross-site scripting (XSS) vulnerability was discovered in the Administrator panel on the 'Setting News' module on CMS Made Simple 2.2.14 which allows an attacker to execute arbitrary web scripts.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cmsmadesimple | Cms Made Simple | 2.2.14 |
Related Weaknesses (CWE)
References
- http://dev.cmsmadesimple.org/bug/view/12317ExploitVendor Advisory
- http://dev.cmsmadesimple.org/bug/view/12317ExploitVendor Advisory
FAQ
What is CVE-2020-27377?
CVE-2020-27377 is a vulnerability with a CVSS score of 4.8 (MEDIUM). A cross-site scripting (XSS) vulnerability was discovered in the Administrator panel on the 'Setting News' module on CMS Made Simple 2.2.14 which allows an attacker to execute arbitrary web scripts.
How severe is CVE-2020-27377?
CVE-2020-27377 has been rated MEDIUM with a CVSS base score of 4.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-27377?
Check the references section above for vendor advisories and patch information. Affected products include: Cmsmadesimple Cms Made Simple.