CVE-2017-7256: XSS
Published Mar 24, 2017
·Updated
XSS exists in the CMS Made Simple (CMSMS) 2.1.6 "Content-->News-->Add Article" feature via the m1summary parameter. Someone must login to conduct the attack.
Affected Software
1 affected component
CMSmadesimple CMS Made Simple=2.1.6
Event History
Mar 24, 2017
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Data Sourced
via NVD·03:59 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2017-7256?
CVE-2017-7256 is classified as a moderate severity vulnerability due to its potential impact on user data.
2
How do I fix CVE-2017-7256?
To remediate CVE-2017-7256, upgrade to the latest version of CMS Made Simple that addresses this vulnerability.
3
What types of attacks can CVE-2017-7256 enable?
CVE-2017-7256 can enable cross-site scripting (XSS) attacks if exploited.
4
Who is affected by CVE-2017-7256?
Users running CMS Made Simple version 2.1.6 are affected by CVE-2017-7256.
5
Do I need to be logged in to exploit CVE-2017-7256?
Yes, an attacker must be logged in to exploit the vulnerability associated with CVE-2017-7256.