CVE-2018-10033: XSS
Published Apr 11, 2018
·Updated
CMS Made Simple (aka CMSMS) 2.2.7 has Stored XSS in admin/siteprefs.php via the metadata parameter.
Affected Software
1 affected component
CMSmadesimple CMS Made Simple<=2.2.7
Event History
Apr 11, 2018
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-10033?
CVE-2018-10033 has been classified as a medium severity vulnerability.
2
How do I fix CVE-2018-10033?
To fix CVE-2018-10033, upgrade CMS Made Simple to version 2.2.8 or later.
3
What kind of vulnerability is CVE-2018-10033?
CVE-2018-10033 is a Stored Cross-Site Scripting (XSS) vulnerability.
4
Which versions of CMS Made Simple are affected by CVE-2018-10033?
CVE-2018-10033 affects versions of CMS Made Simple up to and including 2.2.7.
5
What is the impact of CVE-2018-10033?
The impact of CVE-2018-10033 allows an attacker to execute arbitrary JavaScript in the context of an admin user.