CVE-2023-43339: XSS
Cross-Site Scripting (XSS) vulnerability in cmsmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a crafted payload injected into the Database Name, DataBase User or Database Port components.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2023-43339.
What is the severity of CVE-2023-43339?
The severity of CVE-2023-43339 is medium.
What is the affected software?
The affected software is CMS Made Simple version 2.2.18.
How can a local attacker exploit CVE-2023-43339?
A local attacker can exploit CVE-2023-43339 by injecting a crafted payload into the Database Name, DataBase User, or Database Port components.
Are there any references for more information?
Yes, you can find more information at the following references: [http://www.cmsmadesimple.org/](http://www.cmsmadesimple.org/), [https://github.com/sromanhu/CVE-2023-43339-CMSmadesimple-Reflected-XSS---Installation/blob/main/README.md](https://github.com/sromanhu/CVE-2023-43339-CMSmadesimple-Reflected-XSS---Installation/blob/main/README.md), [https://github.com/sromanhu/Cmsmadesimple-CMS-Stored-XSS/blob/main/README.md](https://github.com/sromanhu/Cmsmadesimple-CMS-Stored-XSS/blob/main/README.md).