CVE-2018-20464: XSS
Published Dec 25, 2018
·Updated
There is a reflected XSS vulnerability in the CMS Made Simple 2.2.8 admin/myaccount.php. This vulnerability is triggered upon an attempt to modify a user's mailbox with the wrong format. The response contains the user's previously entered email address.
Affected Software
1 affected component
CMSmadesimple CMS Made Simple=2.2.8
Event History
Dec 25, 2018
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-20464?
CVE-2018-20464 is classified as a high-severity reflected XSS vulnerability.
2
How do I fix CVE-2018-20464?
To fix CVE-2018-20464, upgrade CMS Made Simple to the latest version that addresses this vulnerability.
3
Who is affected by CVE-2018-20464?
Users of CMS Made Simple version 2.2.8 are affected by CVE-2018-20464.
4
What causes CVE-2018-20464?
CVE-2018-20464 is caused by the improper handling of user input in the admin/myaccount.php file.
5
Is there a workaround for CVE-2018-20464?
Currently, the only reliable workaround for CVE-2018-20464 is to avoid using the impacted features until an upgrade is performed.