CVE-2020-24861: XSS
Published Oct 1, 2020
·Updated
GetSimple CMS 3.3.16 allows in parameter 'permalink' on the Settings page persistent Cross Site Scripting which is executed when you create and open a new page
Affected Software
1 affected component
Get-simple Getsimple Cms=3.3.16
Event History
Oct 1, 2020
CVE Published
via MITRE·01:50 PM
Data Sourced
via MITRE·01:50 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2020-24861.
2
What is the severity rating of CVE-2020-24861?
CVE-2020-24861 has a severity rating of 5.4 (medium).
3
What is the affected software?
The affected software is GetSimple CMS version 3.3.16.
4
What type of vulnerability is CVE-2020-24861?
CVE-2020-24861 is a persistent cross-site scripting (XSS) vulnerability.
5
How can I fix the vulnerability?
To fix CVE-2020-24861, update GetSimple CMS to a version that has addressed the vulnerability.