CVE-2014-1603: XSS
Multiple cross-site scripting (XSS) vulnerabilities in GetSimple CMS 3.3.1 allow remote attackers to inject arbitrary web script or HTML via the (1) param parameter to admin/load.php or (2) user, (3) email, or (4) name parameter in a Save Settings action to admin/settings.php.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-1603?
CVE-2014-1603 is considered a medium severity vulnerability due to its potential for exploitation via cross-site scripting.
How do I fix CVE-2014-1603?
To fix CVE-2014-1603, upgrade GetSimple CMS to the latest version to eliminate the XSS vulnerabilities.
What does CVE-2014-1603 affect?
CVE-2014-1603 specifically affects GetSimple CMS version 3.3.1.
Can CVE-2014-1603 be exploited remotely?
Yes, CVE-2014-1603 can be exploited remotely by attackers to inject malicious scripts.
What are the common attack vectors for CVE-2014-1603?
Common attack vectors for CVE-2014-1603 include manipulating the param, user, email, or name parameters in specific application actions.