First published: Thu Apr 25 2019(Updated: )
The File Manager in CMS Made Simple through 2.2.10 has Reflected XSS via the "New name" field in a Rename action.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cmsmadesimple Cms Made Simple | <=2.2.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2019-11513 is medium with a severity value of 4.8.
CVE-2019-11513 affects CMS Made Simple versions up to and including 2.2.10.
CVE-2019-11513 is a reflected cross-site scripting (XSS) vulnerability.
The vulnerability CVE-2019-11513 can be exploited by injecting malicious code into the "New name" field in a Rename action in the File Manager of CMS Made Simple.
Yes, updating CMS Made Simple to a version above 2.2.10 will fix the vulnerability CVE-2019-11513.