CVE-2017-7257: XSS
Published Mar 24, 2017
·Updated
XSS exists in the CMS Made Simple (CMSMS) 2.1.6 "Content-->News-->Add Article" feature via the m1content parameter. Someone must login to conduct the attack.
Affected Software
1 affected component
CMSmadesimple CMS Made Simple=2.1.6
Event History
Mar 24, 2017
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Data Sourced
via NVD·03:59 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2017-7257?
CVE-2017-7257 is considered a moderate severity vulnerability due to its potential for cross-site scripting (XSS) attacks.
2
How do I fix CVE-2017-7257?
To fix CVE-2017-7257, upgrade CMS Made Simple to version 2.1.7 or later, which addresses this vulnerability.
3
What software is affected by CVE-2017-7257?
CVE-2017-7257 affects CMS Made Simple version 2.1.6.
4
What type of attack is associated with CVE-2017-7257?
CVE-2017-7257 is associated with cross-site scripting (XSS) attacks that require user authentication.
5
Who must be logged in to exploit CVE-2017-7257?
An attacker must be logged in to exploit CVE-2017-7257 through the 'Content-->News-->Add Article' feature.