First published: Wed Oct 16 2019(Updated: )
CMS Made Simple (CMSMS) 2.2.11 allows stored XSS by an admin via a crafted image filename on the "News > Add Article" screen.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cmsmadesimple Cms Made Simple | =2.2.11 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-17630 is a vulnerability in CMS Made Simple (CMSMS) 2.2.11 that allows an admin to execute stored XSS through a crafted image filename on the "News > Add Article" screen.
CVE-2019-17630 has a severity score of 4.8, which is considered medium.
CVE-2019-17630 affects CMS Made Simple version 2.2.11. Other versions may not be affected.
CVE-2019-17630 is classified under CWE category 79: Cross-Site Scripting (XSS).
More information about CVE-2019-17630 can be found at the following references: [Link 1](http://dev.cmsmadesimple.org/bug/view/12149), [Link 2](https://forum.cmsmadesimple.org/viewforum.php?f=1).