CVE-2017-7255: XSS
Published Mar 24, 2017
·Updated
XSS exists in the CMS Made Simple (CMSMS) 2.1.6 "Content-->News-->Add Article" feature via the m1title parameter. Someone must login to conduct the attack.
Affected Software
1 affected component
CMSmadesimple CMS Made Simple=2.1.6
Event History
Mar 24, 2017
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Data Sourced
via NVD·03:59 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2017-7255?
CVE-2017-7255 is categorized with a moderate severity due to its XSS vulnerability that requires user authentication to exploit.
2
How do I fix CVE-2017-7255?
To fix CVE-2017-7255, upgrade to a patched version of CMS Made Simple that addresses the XSS vulnerability.
3
What systems are affected by CVE-2017-7255?
CVE-2017-7255 specifically affects CMS Made Simple version 2.1.6.
4
What is the impact of CVE-2017-7255?
The impact of CVE-2017-7255 allows an authenticated attacker to execute arbitrary JavaScript code in the context of the user's browser session.
5
Is CVE-2017-7255 a remote exploit?
No, CVE-2017-7255 is not a remote exploit; it requires the attacker to be logged into the CMS.