First published: Wed Jun 23 2021(Updated: )
Cross Site Scripting (XSS) vulnerability in GetSimpleCMS <= 3.3.15 in admin/changedata.php via the redirect_url parameter and the headers_sent function.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Get-simple Getsimplecms | <=3.3.15 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2020-18657 is medium with a CVSS score of 6.1.
CVE-2020-18657 is a Cross Site Scripting (XSS) vulnerability in GetSimpleCMS <= 3.3.15 in the admin/changedata.php file.
GetSimpleCMS versions up to and including 3.3.15 are affected by CVE-2020-18657.
Upgrade GetSimpleCMS to a version higher than 3.3.15 to fix CVE-2020-18657.
You can find more information about CVE-2020-18657 at the following references: [Link 1](https://github.com/GetSimpleCMS/GetSimpleCMS/issues/1310), [Link 2](https://github.com/LoRexxar/CVE_Request/blob/master/getsimplecms%20v3.3.15/getsimplecms_before_v3.3.15.md), [Link 3](https://www.seebug.org/vuldb/ssvid-97929).