First published: Thu May 28 2020(Updated: )
CMS Made Simple through 2.2.14 allows XSS via a crafted File Picker profile name.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cmsmadesimple Cms Made Simple | <=2.2.14 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-13660 is a vulnerability in CMS Made Simple through 2.2.14 that allows XSS (cross-site scripting) attacks via a crafted File Picker profile name.
CVE-2020-13660 has a severity score of 4.8 which is considered medium.
CVE-2020-13660 affects CMS Made Simple through version 2.2.14.
CVE-2020-13660 is associated with CWE-79, which is the category for Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').
To mitigate CVE-2020-13660, it is recommended to upgrade CMS Made Simple to a version beyond 2.2.14.