First published: Tue Mar 26 2019(Updated: )
CMS Made Simple 2.2.10 has XSS via the myaccount.php "Email Address" field, which is reachable via the "My Preferences -> My Account" section.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cmsmadesimple Cms Made Simple | =2.2.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this vulnerability is CVE-2019-10107.
The severity of CVE-2019-10107 is medium with a CVSS score of 5.4.
The vulnerability allows for XSS attacks via the "Email Address" field in the "My Preferences -> My Account" section of CMS Made Simple 2.2.10.
Update CMS Made Simple to a version higher than 2.2.10 to mitigate the vulnerability.
You can find more information about CVE-2019-10107 at http://dev.cmsmadesimple.org/bug/view/12003.