First published: Wed Sep 30 2020(Updated: )
CMS Made Simple before 2.2.15 allows XSS via the m1_mod parameter in a ModuleManager local_uninstall action to admin/moduleinterface.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cmsmadesimple Cms Made Simple | <2.2.15 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2020-22842.
CMS Made Simple versions up to and excluding 2.2.15 are affected by CVE-2020-22842.
CVE-2020-22842 allows XSS through the m1_mod parameter in a ModuleManager local_uninstall action to admin/moduleinterface.php.
CVE-2020-22842 has a severity rating of medium, with a CVSS score of 5.4.
Yes, updating CMS Made Simple to version 2.2.15 or newer will fix the vulnerability.