First published: Wed Sep 22 2021(Updated: )
CMS Made Simple 2.2.14 was discovered to contain a cross-site scripting (XSS) vulnerability which allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the Field Definition text field.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cmsmadesimple Cms Made Simple | =2.2.14 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-23481 is a cross-site scripting (XSS) vulnerability in CMS Made Simple 2.2.14.
The severity of CVE-2020-23481 is medium, with a CVSS score of 5.4.
CVE-2020-23481 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the Field Definition text field of CMS Made Simple 2.2.14.
The Common Weakness Enumeration (CWE) ID for CVE-2020-23481 is CWE-79.
You can find more information about CVE-2020-23481 at http://dev.cmsmadesimple.org/bug/view/12317.