CVE-2014-2219: XSS
Cross-site scripting (XSS) vulnerability in whizzywig/wb.php in CMSimple Classic 3.54 and earlier, possibly as downloaded before February 26, 2014, allows remote attackers to inject arbitrary web script or HTML via the d parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-2219?
CVE-2014-2219 is a high severity cross-site scripting (XSS) vulnerability that can allow attackers to inject arbitrary scripts.
How do I fix CVE-2014-2219?
To fix CVE-2014-2219, upgrade to CMSimple Classic version 3.5.5 or later which addresses this vulnerability.
Who is affected by CVE-2014-2219?
CVE-2014-2219 affects users of CMSimple Classic version 3.5.4 and earlier, particularly those downloaded before February 26, 2014.
What type of vulnerability is CVE-2014-2219?
CVE-2014-2219 is classified as a cross-site scripting (XSS) vulnerability.
Can CVE-2014-2219 lead to data theft?
Yes, CVE-2014-2219 can allow attackers to execute malicious scripts, potentially leading to data theft or unauthorized actions.