First published: Tue Jun 01 2021(Updated: )
A cross-site scripting (XSS) vulnerability was discovered in the Administrator panel on the 'Setting News' module on CMS Made Simple 2.2.14 which allows an attacker to execute arbitrary web scripts.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cmsmadesimple Cms Made Simple | =2.2.14 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-27377 is a cross-site scripting (XSS) vulnerability discovered in the Administrator panel on the Setting News module on CMS Made Simple 2.2.14.
CVE-2020-27377 has a severity score of 4.8, which is considered medium severity.
CVE-2020-27377 allows an attacker to execute arbitrary web scripts by exploiting the cross-site scripting vulnerability in the Administrator panel on the Setting News module.
CVE-2020-27377 affects CMS Made Simple version 2.2.14.
CVE-2020-27377 can be fixed by updating CMS Made Simple to a version that is not affected by the vulnerability.