First published: Mon Oct 01 2018(Updated: )
An issue was discovered in GetSimple CMS 3.3.15. An administrator can insert stored XSS via the admin/settings.php Custom Permalink Structure parameter, which injects the XSS payload into any page created at the admin/pages.php URI.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Get-simple Getsimple Cms | =3.3.15 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2018-17835 is medium, with a severity value of 4.8.
CVE-2018-17835 affects GetSimple CMS version 3.3.15.
An administrator can exploit CVE-2018-17835 by inserting stored XSS via the admin/settings.php Custom Permalink Structure parameter.
The impact of CVE-2018-17835 is that an XSS payload can be injected into any page created at the admin/pages.php URI.
Yes, upgrading to a version of GetSimple CMS that is not affected by the vulnerability is the recommended fix for CVE-2018-17835.