CVE-2020-23481: XSS
Published Sep 22, 2021
·Updated
CMS Made Simple 2.2.14 was discovered to contain a cross-site scripting (XSS) vulnerability which allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the Field Definition text field.
Affected Software
1 affected component
CMSmadesimple CMS Made Simple=2.2.14
Event History
Sep 22, 2021
CVE Published
via MITRE·07:47 PM
Data Sourced
via MITRE·07:47 PM
Description
Frequently Asked Questions
1
What is CVE-2020-23481?
CVE-2020-23481 is a cross-site scripting (XSS) vulnerability in CMS Made Simple 2.2.14.
2
What is the severity of CVE-2020-23481?
The severity of CVE-2020-23481 is medium, with a CVSS score of 5.4.
3
How does CVE-2020-23481 affect the affected software?
CVE-2020-23481 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the Field Definition text field of CMS Made Simple 2.2.14.
4
What is the Common Weakness Enumeration (CWE) ID for CVE-2020-23481?
The Common Weakness Enumeration (CWE) ID for CVE-2020-23481 is CWE-79.
5
Where can I find more information about CVE-2020-23481?
You can find more information about CVE-2020-23481 at http://dev.cmsmadesimple.org/bug/view/12317.