CVE-2021-43154: XSS
Cross Site Scripting (XSS) vulnerability exists in CMS Made Simple 2.2.15 via the Name field in an Add Category action in moduleinterface.php.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-43154?
The severity of CVE-2021-43154 is medium with a CVSS score of 6.1.
How does the Cross Site Scripting (XSS) vulnerability impact CMS Made Simple 2.2.15?
The Cross Site Scripting (XSS) vulnerability in CMS Made Simple 2.2.15 allows attackers to execute malicious scripts in a victim's browser.
How can the Cross Site Scripting (XSS) vulnerability in CMS Made Simple 2.2.15 be exploited?
The Cross Site Scripting (XSS) vulnerability in CMS Made Simple 2.2.15 can be exploited by including malicious scripts in the Name field when performing the Add Category action in moduleinterface.php.
Is there a fix available for CVE-2021-43154?
Yes, upgrading to a version of CMS Made Simple that is not affected by the vulnerability (2.2.16 or above) will fix CVE-2021-43154.
Where can I find more information about the Cross Site Scripting (XSS) vulnerability in CMS Made Simple 2.2.15?
Additional information about the Cross Site Scripting (XSS) vulnerability in CMS Made Simple 2.2.15 can be found at https://elprofesor.me/2021/10/24/stored-cross-site-scripting-via-m1-name-authenticated.