CVE-2020-24860: XSS
CMS Made Simple 2.2.14 allows an authenticated user with access to the Content Manager to edit content and put persistent XSS payload in the affected text fields. The user can get cookies from every authenticated user who visits the website.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-24860?
CVE-2020-24860 is a vulnerability in CMS Made Simple 2.2.14 that allows an authenticated user with access to the Content Manager to edit content and execute persistent cross-site scripting (XSS) attacks.
How does CVE-2020-24860 work?
An authenticated user with access to the Content Manager can edit content and insert malicious XSS payloads into the affected text fields, which can then be executed when another authenticated user visits the website and their cookies can be stolen.
What is the severity of CVE-2020-24860?
CVE-2020-24860 has a severity rating of medium with a CVSS score of 5.4.
How can I fix CVE-2020-24860?
Upgrade CMS Made Simple to a version higher than 2.2.14 to mitigate the vulnerability.
Where can I find more information about CVE-2020-24860?
You can find more information about CVE-2020-24860 on the CMS Made Simple website and the provided references.