CVE-2018-19845: XSS
Published Dec 31, 2018
·Updated
There is Stored XSS in GetSimple CMS 3.3.12 via the admin/edit.php "post-menu" parameter, a related issue to CVE-2018-16325.
Affected Software
1 affected component
Get-simple Getsimple Cms=3.3.12
Event History
Dec 31, 2018
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-19845?
The severity of CVE-2018-19845 is medium with a CVSS score of 5.4.
2
What is the affected software of CVE-2018-19845?
The affected software is GetSimple CMS version 3.3.12.
3
How does the vulnerability in CVE-2018-19845 occur?
The vulnerability in CVE-2018-19845 occurs due to stored XSS in the admin/edit.php "post-menu" parameter of GetSimple CMS.
4
Is there a fix available for CVE-2018-19845?
Yes, the fix for CVE-2018-19845 is to update GetSimple CMS to a version that is not vulnerable.
5
Where can I find more information about CVE-2018-19845?
You can find more information about CVE-2018-19845 [here](https://github.com/security-breachlock/CVE-2018-19845/blob/master/XSS.pdf).