CVE-2017-6556: XSS
Published Mar 9, 2017
·Updated
Cross-site scripting (XSS) vulnerability in CMS Made Simple (CMSMS) 2.1.6 allows remote authenticated users to inject arbitrary web script or HTML via the "adminpage > sitesetting > General Settings > globalmetadata" field.
Affected Software
1 affected component
CMSmadesimple CMS Made Simple=2.1.6
Event History
Mar 9, 2017
CVE Published
via MITRE·09:26 AM
Data Sourced
via MITRE·09:26 AM
Description
Data Sourced
via NVD·09:59 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2017-6556?
The severity of CVE-2017-6556 is considered medium, due to its cross-site scripting capabilities.
2
How do I fix CVE-2017-6556?
To fix CVE-2017-6556, upgrade to a patched version of CMS Made Simple, specifically a version higher than 2.1.6.
3
Who is affected by CVE-2017-6556?
Users of CMS Made Simple version 2.1.6 with authenticated access are affected by CVE-2017-6556.
4
What type of vulnerability is CVE-2017-6556?
CVE-2017-6556 is a cross-site scripting (XSS) vulnerability.
5
What can attackers do using CVE-2017-6556?
Attackers can inject arbitrary web scripts or HTML through the globalmetadata field in the admin settings.