CVE-2018-10029: XSS
Published Apr 11, 2018
·Updated
CMS Made Simple (aka CMSMS) 2.2.7 has Reflected XSS in admin/moduleinterface.php via the m1name parameter, related to moduledepends, a different vulnerability than CVE-2017-16799.
Affected Software
1 affected component
CMSmadesimple CMS Made Simple<=2.2.7
Event History
Apr 11, 2018
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-10029?
CVE-2018-10029 has a medium severity rating due to its potential for reflected cross-site scripting.
2
How do I fix CVE-2018-10029?
To fix CVE-2018-10029, update CMS Made Simple to a version later than 2.2.7.
3
What type of vulnerability is CVE-2018-10029?
CVE-2018-10029 is a reflected cross-site scripting vulnerability.
4
What parameter is vulnerable in CVE-2018-10029?
The vulnerable parameter in CVE-2018-10029 is the m1_name parameter in admin/moduleinterface.php.
5
Does CVE-2018-10029 affect all versions of CMS Made Simple?
CVE-2018-10029 specifically affects CMS Made Simple version 2.2.7 and earlier.