CVE-2018-16325: XSS
Published Sep 1, 2018
·Updated
There is XSS in GetSimple CMS 3.4.0.9 via the admin/edit.php title field.
Affected Software
1 affected component
Get-simple Getsimple Cms=3.4.0.9
Remediation
Patch Available
Event History
Sep 1, 2018
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this XSS vulnerability?
The vulnerability ID for this XSS vulnerability is CVE-2018-16325.
2
What is the affected software version?
The affected software version is GetSimple CMS 3.4.0.9.
3
How severe is this vulnerability?
This vulnerability has a severity rating of 6.1, which is considered medium.
4
How can an attacker exploit this vulnerability?
An attacker can exploit this vulnerability by injecting malicious script code into the title field on the admin/edit.php page of the GetSimple CMS.
5
Is there a fix available for this vulnerability?
Yes, the fix for this vulnerability is available in the latest version of GetSimple CMS. It is recommended to update to the latest version to mitigate the risk.