CVE-2020-36412: XSS
Published Jul 2, 2021
·Updated
A stored cross scripting (XSS) vulnerability in CMS Made Simple 2.2.14 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "Search Text" field under the "Admin Search" module.
Affected Software
1 affected component
CMSmadesimple CMS Made Simple=2.2.14
Event History
Jul 2, 2021
CVE Published
via MITRE·05:51 PM
Data Sourced
via MITRE·05:51 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-36412?
The severity of CVE-2020-36412 is medium with a CVSS score of 5.4.
2
How does the stored cross scripting (XSS) vulnerability in CMS Made Simple 2.2.14 impact the system?
Authenticated attackers can execute arbitrary web scripts or HTML by entering a crafted payload into the "Search Text" field under the "Admin Search" module.
3
Which version of CMS Made Simple is affected by CVE-2020-36412?
Only version 2.2.14 of CMS Made Simple is affected by CVE-2020-36412.
4
Is authentication required to exploit the stored cross scripting (XSS) vulnerability in CMS Made Simple 2.2.14?
Yes, authentication is required to exploit the stored cross scripting (XSS) vulnerability in CMS Made Simple 2.2.14.
5
Is there a fix available for CVE-2020-36412?
Yes, it is recommended to upgrade CMS Made Simple to a version higher than 2.2.14 to fix CVE-2020-36412.