First published: Mon Feb 28 2022(Updated: )
CMS Made Simple v2.2.15 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the parameter m1_fmmessage.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cmsmadesimple Cms Made Simple | =2.2.15 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-23907 is a reflected cross-site scripting (XSS) vulnerability found in CMS Made Simple v2.2.15.
CVE-2022-23907 allows an attacker to inject malicious code into a website's HTML content, potentially leading to unauthorized actions or data theft.
CVE-2022-23907 has a severity level of medium with a CVSS score of 6.1.
To fix CVE-2022-23907, it is recommended to upgrade CMS Made Simple to a version that has patched the vulnerability.
More information about CVE-2022-23907 can be found at http://dev.cmsmadesimple.org/bug/view/12503.