CVE-2023-43355: XSS
Cross Site Scripting vulnerability in CMSmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a crafted script to the password and password again parameters in the My Preferences - Add user component.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-43355?
The severity of CVE-2023-43355 is medium with a severity score of 5.4.
How does the Cross Site Scripting vulnerability in CMSmadesimple v.2.2.18 occur?
The Cross Site Scripting vulnerability in CMSmadesimple v.2.2.18 occurs when a local attacker executes arbitrary code via a crafted script to the password and password again parameters in the My Preferences - Add user component.
Which software versions are affected by CVE-2023-43355?
The version 2.2.18 of CMSmadesimple, specifically Cms Made Simple, is affected by CVE-2023-43355.
Is there a fix available for CVE-2023-43355?
At the moment, there is no fix available for CVE-2023-43355. It is recommended to stay updated with the latest security patches and monitor the vendor's website for any updates.
What is the Common Weakness Enumeration ID associated with CVE-2023-43355?
The Common Weakness Enumeration (CWE) ID associated with CVE-2023-43355 is 79.