CVE-2018-17835: XSS
Published Oct 1, 2018
·Updated
An issue was discovered in GetSimple CMS 3.3.15. An administrator can insert stored XSS via the admin/settings.php Custom Permalink Structure parameter, which injects the XSS payload into any page created at the admin/pages.php URI.
Affected Software
1 affected component
Get-simple Getsimple Cms=3.3.15
Event History
Oct 1, 2018
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-17835?
The severity of CVE-2018-17835 is medium, with a severity value of 4.8.
2
How does CVE-2018-17835 affect GetSimple CMS?
CVE-2018-17835 affects GetSimple CMS version 3.3.15.
3
How can an administrator exploit CVE-2018-17835?
An administrator can exploit CVE-2018-17835 by inserting stored XSS via the admin/settings.php Custom Permalink Structure parameter.
4
What is the impact of CVE-2018-17835?
The impact of CVE-2018-17835 is that an XSS payload can be injected into any page created at the admin/pages.php URI.
5
Is there a fix for CVE-2018-17835?
Yes, upgrading to a version of GetSimple CMS that is not affected by the vulnerability is the recommended fix for CVE-2018-17835.