CVE-2021-28935: XSS
Published Mar 30, 2021
·Updated
CMS Made Simple (CMSMS) 2.2.15 allows authenticated XSS via the /admin/addbookmark.php script through the Site Admin > My Preferences > Title field.
Affected Software
1 affected component
CMSmadesimple CMS Made Simple=2.2.15
Event History
Mar 30, 2021
CVE Published
via MITRE·12:00 PM
Data Sourced
via MITRE·12:00 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2021-28935.
2
What is the title of this vulnerability?
The title of this vulnerability is CMS Made Simple (CMSMS) 2.2.15 allows authenticated XSS via the /admin/addbookmark.php script.
3
How can the vulnerability be exploited?
The vulnerability can be exploited by authenticated users through the Site Admin > My Preferences > Title field.
4
What is the affected software version?
The affected software version is CMS Made Simple (CMSMS) 2.2.15.
5
How severe is this vulnerability?
This vulnerability has a severity value of 5.4, which is considered medium.