First published: Wed Jun 05 2019(Updated: )
CMS Made Simple 2.2.10 has XSS via the m1_name parameter in "Add Article" under Content -> Content Manager -> News.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cmsmadesimple Cms Made Simple | =2.2.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-11226 is a vulnerability in CMS Made Simple 2.2.10 that allows for cross-site scripting (XSS) attacks.
CVE-2019-11226 has a severity score of 5.4, which is considered medium.
CVE-2019-11226 affects CMS Made Simple 2.2.10 by exploiting the m1_name parameter in the "Add Article" feature under Content Manager->News, allowing for XSS attacks.
To fix CVE-2019-11226, update CMS Made Simple to a version that is not affected, or apply the necessary patches provided by the vendor.
For more information about CVE-2019-11226, you can refer to the following references: [link1], [link2], [link3].