CVE-2018-18270: XSS
Published Oct 12, 2018
·Updated
XSS exists in CMS Made Simple version 2.2.7 via the m1newsurl parameter in an admin/moduleinterface.php "Content-->News-->Add Article" action.
Affected Software
1 affected component
CMSmadesimple CMS Made Simple=2.2.7
Event History
Oct 12, 2018
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-18270?
CVE-2018-18270 is classified as a high severity vulnerability due to its potential for cross-site scripting (XSS) attacks.
2
How do I fix CVE-2018-18270?
To fix CVE-2018-18270, update CMS Made Simple to the latest version beyond 2.2.7.
3
What is the impact of CVE-2018-18270?
CVE-2018-18270 allows attackers to inject malicious scripts into web pages viewed by administrators, compromising the security of the CMS.
4
Which versions are affected by CVE-2018-18270?
CVE-2018-18270 specifically affects CMS Made Simple version 2.2.7.
5
How is CVE-2018-18270 exploited?
CVE-2018-18270 can be exploited through the m1_news_url parameter in the admin module interface when adding articles.