First published: Fri Oct 20 2023(Updated: )
Cross Site Scripting vulnerability in CMSmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a crafted script to the password and password again parameters in the My Preferences - Add user component.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cmsmadesimple Cms Made Simple | =2.2.18 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-43355 is medium with a severity score of 5.4.
The Cross Site Scripting vulnerability in CMSmadesimple v.2.2.18 occurs when a local attacker executes arbitrary code via a crafted script to the password and password again parameters in the My Preferences - Add user component.
The version 2.2.18 of CMSmadesimple, specifically Cms Made Simple, is affected by CVE-2023-43355.
At the moment, there is no fix available for CVE-2023-43355. It is recommended to stay updated with the latest security patches and monitor the vendor's website for any updates.
The Common Weakness Enumeration (CWE) ID associated with CVE-2023-43355 is 79.