First published: Mon Dec 31 2018(Updated: )
There is Stored XSS in GetSimple CMS 3.3.12 via the admin/edit.php "post-menu" parameter, a related issue to CVE-2018-16325.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Get-simple Getsimple Cms | =3.3.12 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2018-19845 is medium with a CVSS score of 5.4.
The affected software is GetSimple CMS version 3.3.12.
The vulnerability in CVE-2018-19845 occurs due to stored XSS in the admin/edit.php "post-menu" parameter of GetSimple CMS.
Yes, the fix for CVE-2018-19845 is to update GetSimple CMS to a version that is not vulnerable.
You can find more information about CVE-2018-19845 [here](https://github.com/security-breachlock/CVE-2018-19845/blob/master/XSS.pdf).