CVE-2015-5356: XSS
Published Jul 1, 2015
·Updated
Cross-site scripting (XSS) vulnerability in admin/filebrowser.php in GetSimple CMS before 3.3.6 allows remote attackers to inject arbitrary web script or HTML via the func parameter.
Affected Software
1 affected component
Get-simple Getsimple Cms<=3.3.2
Event History
Jul 1, 2015
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-5356?
CVE-2015-5356 is classified as a medium severity vulnerability due to its potential for remote exploitation via cross-site scripting.
2
How do I fix CVE-2015-5356?
To fix CVE-2015-5356, upgrade your GetSimple CMS installation to version 3.3.6 or later.
3
Who is affected by CVE-2015-5356?
CVE-2015-5356 affects users of GetSimple CMS versions prior to 3.3.6.
4
What type of vulnerability is CVE-2015-5356?
CVE-2015-5356 is a cross-site scripting (XSS) vulnerability.
5
What components of GetSimple CMS are impacted by CVE-2015-5356?
CVE-2015-5356 specifically impacts the admin/filebrowser.php script within GetSimple CMS.