First published: Thu Jan 25 2018(Updated: )
CMS Made Simple (CMSMS) 2.2.5 has XSS in admin/moduleinterface.php via the m1_messages parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
CMS Made Simple | =2.2.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-5964 has a medium severity rating due to its potential for XSS attacks.
To fix CVE-2018-5964, upgrade CMS Made Simple to version 2.2.6 or later.
CVE-2018-5964 is a Cross-Site Scripting (XSS) vulnerability.
CVE-2018-5964 affects users of CMS Made Simple version 2.2.5.
CVE-2018-5964 can be exploited via malicious input in the m1_messages parameter in the admin interface.