CVE-2014-2092: XSS
Cross-site scripting (XSS) vulnerability in lib/filemanager/ImageManager/editorFrame.php in CMS Made Simple 1.11.10 allows remote attackers to inject arbitrary web script or HTML via the action parameter, a different issue than CVE-2014-0334. NOTE: the original disclosure also reported issues that may not cross privilege boundaries.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-2092?
CVE-2014-2092 is classified as a medium severity cross-site scripting (XSS) vulnerability.
How do I fix CVE-2014-2092?
To fix CVE-2014-2092, upgrade to a patched version of CMS Made Simple that addresses this vulnerability.
What software is affected by CVE-2014-2092?
CVE-2014-2092 specifically affects CMS Made Simple version 1.11.10.
What type of vulnerability is CVE-2014-2092?
CVE-2014-2092 is a cross-site scripting (XSS) vulnerability that allows attackers to inject arbitrary web scripts or HTML.
Are there any known exploits for CVE-2014-2092?
Yes, there are potential exploits for CVE-2014-2092 that leverage the XSS vulnerability in CMS Made Simple.