CVE-2020-13660: XSS
Published May 28, 2020
·Updated
CMS Made Simple through 2.2.14 allows XSS via a crafted File Picker profile name.
Affected Software
1 affected component
CMSmadesimple CMS Made Simple<=2.2.14
Event History
May 28, 2020
CVE Published
via MITRE·06:53 PM
Data Sourced
via MITRE·06:53 PM
Description
Frequently Asked Questions
1
What is CVE-2020-13660?
CVE-2020-13660 is a vulnerability in CMS Made Simple through 2.2.14 that allows XSS (cross-site scripting) attacks via a crafted File Picker profile name.
2
How severe is CVE-2020-13660?
CVE-2020-13660 has a severity score of 4.8 which is considered medium.
3
How does CVE-2020-13660 affect CMS Made Simple?
CVE-2020-13660 affects CMS Made Simple through version 2.2.14.
4
What is the Common Weakness Enumeration (CWE) for CVE-2020-13660?
CVE-2020-13660 is associated with CWE-79, which is the category for Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').
5
How can CVE-2020-13660 be mitigated?
To mitigate CVE-2020-13660, it is recommended to upgrade CMS Made Simple to a version beyond 2.2.14.