First published: Sun Oct 14 2007(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in CMS Made Simple 1.1.3.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors related to (1) the anchor tag and (2) listtags.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Simple CMS | =1.1.3.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-5443 is classified as a moderate severity vulnerability due to its potential for cross-site scripting attacks.
To fix CVE-2007-5443, upgrade CMS Made Simple to version 1.4.1 or later, where the vulnerabilities have been addressed.
CVE-2007-5443 allows remote attackers to perform cross-site scripting attacks, injecting arbitrary web scripts or HTML into affected sites.
CVE-2007-5443 specifically affects CMS Made Simple version 1.1.3.1.
Any users running CMS Made Simple version 1.1.3.1 may be vulnerable to CVE-2007-5443 unless they have updated to a secure version.