CVE-2017-6555: XSS
Cross-site scripting (XSS) vulnerability in /admin/moduleinterface.php in CMS Made Simple 2.1.6 allows remote authenticated users to inject arbitrary web script or HTML via the m1description parameter (aka "Design Manager > Categories > Category Description").
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-6555?
CVE-2017-6555 is classified as a medium severity vulnerability due to its potential for remote code execution through XSS.
How do I fix CVE-2017-6555?
The recommended fix for CVE-2017-6555 is to update CMS Made Simple to a later version that addresses this vulnerability.
What systems are affected by CVE-2017-6555?
CVE-2017-6555 specifically affects CMS Made Simple version 2.1.6.
How does CVE-2017-6555 work?
CVE-2017-6555 allows remote authenticated users to inject arbitrary web scripts or HTML via the m1_description parameter.
What is the impact of CVE-2017-6555?
The impact of CVE-2017-6555 includes potential exploitation of XSS to hijack user sessions or perform malicious actions on behalf of users.