CVE-2020-21353: XSS
Published Aug 6, 2021
·Updated
A stored cross site scripting (XSS) vulnerability in /admin/snippets.php of GetSimple CMS 3.4.0a allows attackers to execute arbitrary web scripts or HTML via crafted payload in the Edit Snippets module.
Affected Software
1 affected component
Get-simple Getsimplecms=3.4.0a
Event History
Aug 6, 2021
CVE Published
via MITRE·10:36 PM
Data Sourced
via MITRE·10:36 PM
Description
Frequently Asked Questions
1
What is CVE-2020-21353?
CVE-2020-21353 is a stored cross-site scripting (XSS) vulnerability in GetSimple CMS 3.4.0a.
2
What is the severity of CVE-2020-21353?
The severity of CVE-2020-21353 is medium with a CVSS score of 5.4.
3
How does CVE-2020-21353 affect GetSimple CMS?
CVE-2020-21353 allows attackers to execute arbitrary web scripts or HTML via crafted payload in the Edit Snippets module of GetSimple CMS 3.4.0a.
4
What is the Common Weakness Enumeration (CWE) for CVE-2020-21353?
The CWE for CVE-2020-21353 is CWE-79 (Improper Neutralization of Input During Web Page Generation).
5
How can I fix CVE-2020-21353 in GetSimple CMS?
To fix CVE-2020-21353, it is recommended to update GetSimple CMS to a version that has patched the vulnerability.