CVE-2017-10673: XSS
Published Jun 29, 2017
·Updated
admin/profile.php in GetSimple CMS 3.x has XSS in a name field.
Affected Software
12 affected components
Get-simple Getsimple Cms=3.0
Get-simple Getsimple Cms=3.1
Get-simple Getsimple Cms=3.1.1
Get-simple Getsimple Cms=3.1.2
Get-simple Getsimple Cms=3.2
Get-simple Getsimple Cms=3.2.1
Get-simple Getsimple Cms=3.2.2
Get-simple Getsimple Cms=3.2.3
Get-simple Getsimple Cms=3.3.0
Get-simple Getsimple Cms=3.3.1
Get-simple Getsimple Cms=3.3.2
Get-simple Getsimple Cms=3.3.2-b3
Remediation
Patch Available
Event History
Jun 29, 2017
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-10673?
CVE-2017-10673 has a moderate severity rating due to its potential for cross-site scripting (XSS) attacks.
2
How do I fix CVE-2017-10673?
To fix CVE-2017-10673, you should update GetSimple CMS to version 3.3.2 or higher.
3
What impact does CVE-2017-10673 have on my website?
CVE-2017-10673 allows an attacker to inject malicious scripts into the admin profile name field, potentially compromising user sessions.
4
Which versions of GetSimple CMS are affected by CVE-2017-10673?
Versions 3.0 to 3.3.1 of GetSimple CMS are affected by CVE-2017-10673.
5
How can I test for the presence of CVE-2017-10673 on my site?
You can test for CVE-2017-10673 by attempting to inject JavaScript code into the name field in the admin profile section and checking for execution.