CVE-2020-36416: XSS
Published Jul 2, 2021
·Updated
A stored cross scripting (XSS) vulnerability in CMS Made Simple 2.2.14 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "Create a new Design" parameter under the "Designs" module.
Affected Software
1 affected component
CMSmadesimple CMS Made Simple=2.2.14
Event History
Jul 2, 2021
CVE Published
via MITRE·05:52 PM
Data Sourced
via MITRE·05:52 PM
Description
Frequently Asked Questions
1
What is CVE-2020-36416?
CVE-2020-36416 is a stored cross-site scripting (XSS) vulnerability in CMS Made Simple 2.2.14.
2
How can an attacker exploit CVE-2020-36416?
An authenticated attacker can exploit CVE-2020-36416 by entering a crafted payload into the "Create a new Design" parameter under the "Designs" module.
3
What is the severity of CVE-2020-36416?
The severity of CVE-2020-36416 is medium (CVSS score 5.4).
4
Which version of CMS Made Simple is affected?
CMS Made Simple version 2.2.14 is affected by CVE-2020-36416.
5
How can I fix CVE-2020-36416?
To fix CVE-2020-36416, it is recommended to update CMS Made Simple to a version that is not affected by the vulnerability.