CVE-2022-23907: XSS
Published Feb 28, 2022
·Updated
CMS Made Simple v2.2.15 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the parameter m1fmmessage.
Affected Software
1 affected component
CMSmadesimple CMS Made Simple=2.2.15
Event History
Feb 28, 2022
CVE Published
via MITRE·10:55 PM
Data Sourced
via MITRE·10:55 PM
Description
Frequently Asked Questions
1
What is CVE-2022-23907?
CVE-2022-23907 is a reflected cross-site scripting (XSS) vulnerability found in CMS Made Simple v2.2.15.
2
How does CVE-2022-23907 impact CMS Made Simple?
CVE-2022-23907 allows an attacker to inject malicious code into a website's HTML content, potentially leading to unauthorized actions or data theft.
3
What is the severity of CVE-2022-23907?
CVE-2022-23907 has a severity level of medium with a CVSS score of 6.1.
4
How can I fix CVE-2022-23907 in CMS Made Simple?
To fix CVE-2022-23907, it is recommended to upgrade CMS Made Simple to a version that has patched the vulnerability.
5
Where can I find more information about CVE-2022-23907?
More information about CVE-2022-23907 can be found at http://dev.cmsmadesimple.org/bug/view/12503.