CVE-2020-36410: XSS
Published Jul 2, 2021
·Updated
A stored cross scripting (XSS) vulnerability in CMS Made Simple 2.2.14 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "Email address to receive notification of news submission" parameter under the "Options" module.
Affected Software
1 affected component
CMSmadesimple CMS Made Simple=2.2.14
Event History
Jul 2, 2021
CVE Published
via MITRE·05:51 PM
Data Sourced
via MITRE·05:51 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-36410?
The severity of CVE-2020-36410 is medium with a CVSS score of 5.4.
2
How does the stored cross scripting vulnerability in CMS Made Simple 2.2.14 affect the system?
The vulnerability allows authenticated attackers to execute arbitrary web scripts or HTML.
3
Who can exploit this vulnerability?
Only authenticated attackers can exploit this vulnerability in CMS Made Simple 2.2.14.
4
What is the affected software version?
The affected software version is CMS Made Simple 2.2.14.
5
Is there a fix available for CVE-2020-36410?
Yes, there is a fix available. It is recommended to update to the latest version of CMS Made Simple.