CVE-2023-36970: XSS
Published Jul 6, 2023
·Updated
A Cross-site scripting (XSS) vulnerability in CMS Made Simple v2.2.17 allows remote attackers to inject arbitrary web script or HTML via the File Upload function.
Affected Software
1 affected component
CMSmadesimple CMS Made Simple=2.2.17
Event History
Jul 6, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-36970?
The severity of CVE-2023-36970 is medium with a score of 5.4.
2
What is the vulnerability in CMS Made Simple v2.2.17?
The vulnerability in CMS Made Simple v2.2.17 is a Cross-site scripting (XSS) vulnerability.
3
How does the vulnerability in CMS Made Simple v2.2.17 impact remote attackers?
The vulnerability in CMS Made Simple v2.2.17 allows remote attackers to inject arbitrary web script or HTML via the File Upload function.
4
What is the Common Weakness Enumeration (CWE) ID of CVE-2023-36970?
The Common Weakness Enumeration (CWE) ID of CVE-2023-36970 is 79.
5
Is there a reference for more information about CVE-2023-36970?
Yes, you can find more information about CVE-2023-36970 at the following link: [CVE-2023-36970 Reference](https://okankurtulus.com.tr/2023/06/27/cms-made-simple-v2-2-17-stored-cross-site-scripting-xss-authenticated/)