CVE-2020-27377: XSS
A cross-site scripting (XSS) vulnerability was discovered in the Administrator panel on the 'Setting News' module on CMS Made Simple 2.2.14 which allows an attacker to execute arbitrary web scripts.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-27377?
CVE-2020-27377 is a cross-site scripting (XSS) vulnerability discovered in the Administrator panel on the Setting News module on CMS Made Simple 2.2.14.
How severe is CVE-2020-27377?
CVE-2020-27377 has a severity score of 4.8, which is considered medium severity.
How does CVE-2020-27377 allow attackers to exploit the vulnerability?
CVE-2020-27377 allows an attacker to execute arbitrary web scripts by exploiting the cross-site scripting vulnerability in the Administrator panel on the Setting News module.
What software versions are affected by CVE-2020-27377?
CVE-2020-27377 affects CMS Made Simple version 2.2.14.
Is there a fix for CVE-2020-27377?
CVE-2020-27377 can be fixed by updating CMS Made Simple to a version that is not affected by the vulnerability.